#Scugbe
#LLUniteBE
#BEEMUG
Manage Configuration Manager
internet clients with the Cloud
Management Gateway
Gerry Hampson
Senior Consultant
Blog: gerryhampsoncm.blogspot.com
Twitter: @GerryHampson
Thanks to our event sponsors
Silver
Platinum
#Scugbe #LLUniteBE #BEEMUG
About me
@GerryHampson
Blog: gerryhampsoncm.blogspot.com
The Cloud-Management-Gateway (my version)
----------
Managing clients with the CMG
Adding the CMGIntroduction to the CMG
Agenda
Using the CMGPrerequisites for the CMG
Implementing the Cloud
Management Gateway
Planning for the Cloud
Management Gateway
Certificates for the CMG
Introduction to the
Cloud Management
Gateway
• Traditional AD joined Windows clients
• Windows 10 Azure AD joined clients
• Install the ConfigMgr client over the internet
• Software updates and endpoint protection
• Inventory and client status
• Compliance settings
• Software distribution
• Windows 10 in-place upgrade task sequence
Typical CMG scenarios
• ARM-based deployment
• Multiple instances
• Support for 96,000 clients per CMG instance
• Support for Management Point & Software Update Point
What can CMG deliver?
• DP hosted in Azure
• Optional component in CMG scenario
• Cloud DP features
• CMG and CDP co-exist
• Intranet and internet based
• Fallback content location
• Distribution Point Groups
• Content encrypted
• Scales well
• Cloud DP limitations
• PXE
• Packages that run directly
• Pre-staged/App-V streaming
• Pull DPs
Cloud Distribution Point
How does CMG
work?
Domain Contoller
Certificate Authority
INTRANET
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
INTRANET
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
Cloud Management
Gateway Connection Point
INTRANET
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
Cloud Management
Gateway Connection Point
INTRANET
Cloud Management
Gateway
Cloud DP
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
Cloud Management
Gateway Connection Point
INTRANET
Cloud Management
Gateway
Cloud DP
INTERNET
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
Cloud Management
Gateway Connection Point
INTRANET
Cloud Management
Gateway
Cloud DP
INTERNET
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
Cloud Management
Gateway Connection Point
INTRANET
Cloud Management
Gateway
Cloud DP
INTERNET
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
Cloud Management
Gateway Connection Point
INTRANET
Cloud Management
Gateway
Cloud DP
INTERNET
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
Cloud Management
Gateway Connection Point
INTRANET
Cloud Management
Gateway
Cloud DP
INTERNET
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
Cloud Management
Gateway Connection Point
INTRANET
Cloud Management
Gateway
Cloud DP
INTERNET
• Virtual Machine
• Standard A2 VM
• Varies by region
• Outbound data transfer
• Data egress
• Content storage
• No cost for software updates
• CMG requires CDP for other content
CMG Cost
Prerequisites for the
Cloud Management
Gateway
• Windows clients
• ConfigMgr site (1610 or later)
• Service Connection Point (Online mode)
• Cloud Management Gateway Connection Point
• Internal Certificate Authority (autoenrollment)
• Public SSL certificate
• Externally routable domain
• Cloud Service name
• Access to DNS records
• Azure subscription
General requirements
• No inbound
• Outbound
• 443 for a single VM
• 10124 & 10125 for 2 VMs
• 10124, 10125 & 10126 for 3 VMs
• Etc up to 16 (10124 up to 10139)
Firewall Ports
Cloud Service name
Demo
Certificates for the
Cloud Management
Gateway
• Cloud Management Gateway
• Azure Management Certificate
• Cloud Management Gateway Certificate
• Internal root certificate
• Cloud Distribution Point (optional)
• Azure Management Certificate
• Cloud Distribution Point Certificate
• Clients
• Client Authentication Certificate
• CMG Connection Point
• Client Authentication Certificate
Certificates
Certificates
Demo
Adding the Cloud
Management Gateway
Create CMG & CMG Connection Point
Demo
Configuring and
monitoring the Cloud
Management Gateway
• Configure MP to allow CMG traffic
• Configure SUP to allow CMG traffic
• CMG Connection Analyser
• Cloud Management dashboard
Using the CMG
Configure MP and SUP
CMG Analyser, Cloud Management dashboard
Demo
Managing clients with
the Cloud Management
Gateway
Client settings, Windows 10 client, tips and tricks
Demo
Cloud Management
Gateway issue
Thanks to our event sponsors
Silver
Platinum
#Scugbe #LLUniteBE #BEEMUG

Llunitebe2018 configuring a cmg in config mgr cb

  • 1.
    #Scugbe #LLUniteBE #BEEMUG Manage Configuration Manager internetclients with the Cloud Management Gateway Gerry Hampson Senior Consultant Blog: gerryhampsoncm.blogspot.com Twitter: @GerryHampson
  • 2.
    Thanks to ourevent sponsors Silver Platinum #Scugbe #LLUniteBE #BEEMUG
  • 3.
  • 4.
  • 5.
    Managing clients withthe CMG Adding the CMGIntroduction to the CMG Agenda Using the CMGPrerequisites for the CMG Implementing the Cloud Management Gateway Planning for the Cloud Management Gateway Certificates for the CMG
  • 6.
    Introduction to the CloudManagement Gateway
  • 7.
    • Traditional ADjoined Windows clients • Windows 10 Azure AD joined clients • Install the ConfigMgr client over the internet • Software updates and endpoint protection • Inventory and client status • Compliance settings • Software distribution • Windows 10 in-place upgrade task sequence Typical CMG scenarios
  • 8.
    • ARM-based deployment •Multiple instances • Support for 96,000 clients per CMG instance • Support for Management Point & Software Update Point What can CMG deliver?
  • 9.
    • DP hostedin Azure • Optional component in CMG scenario • Cloud DP features • CMG and CDP co-exist • Intranet and internet based • Fallback content location • Distribution Point Groups • Content encrypted • Scales well • Cloud DP limitations • PXE • Packages that run directly • Pre-staged/App-V streaming • Pull DPs Cloud Distribution Point
  • 10.
  • 11.
  • 12.
    Primary Site Server ManagementPoint Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point INTRANET
  • 13.
    Primary Site Server ManagementPoint Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point Cloud Management Gateway Connection Point INTRANET
  • 14.
    Primary Site Server ManagementPoint Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point Cloud Management Gateway Connection Point INTRANET Cloud Management Gateway Cloud DP
  • 15.
    Primary Site Server ManagementPoint Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point Cloud Management Gateway Connection Point INTRANET Cloud Management Gateway Cloud DP INTERNET
  • 16.
    Primary Site Server ManagementPoint Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point Cloud Management Gateway Connection Point INTRANET Cloud Management Gateway Cloud DP INTERNET
  • 17.
    Primary Site Server ManagementPoint Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point Cloud Management Gateway Connection Point INTRANET Cloud Management Gateway Cloud DP INTERNET
  • 18.
    Primary Site Server ManagementPoint Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point Cloud Management Gateway Connection Point INTRANET Cloud Management Gateway Cloud DP INTERNET
  • 19.
    Primary Site Server ManagementPoint Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point Cloud Management Gateway Connection Point INTRANET Cloud Management Gateway Cloud DP INTERNET
  • 20.
    Primary Site Server ManagementPoint Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point Cloud Management Gateway Connection Point INTRANET Cloud Management Gateway Cloud DP INTERNET
  • 21.
    • Virtual Machine •Standard A2 VM • Varies by region • Outbound data transfer • Data egress • Content storage • No cost for software updates • CMG requires CDP for other content CMG Cost
  • 22.
    Prerequisites for the CloudManagement Gateway
  • 23.
    • Windows clients •ConfigMgr site (1610 or later) • Service Connection Point (Online mode) • Cloud Management Gateway Connection Point • Internal Certificate Authority (autoenrollment) • Public SSL certificate • Externally routable domain • Cloud Service name • Access to DNS records • Azure subscription General requirements
  • 24.
    • No inbound •Outbound • 443 for a single VM • 10124 & 10125 for 2 VMs • 10124, 10125 & 10126 for 3 VMs • Etc up to 16 (10124 up to 10139) Firewall Ports
  • 25.
  • 26.
    Certificates for the CloudManagement Gateway
  • 27.
    • Cloud ManagementGateway • Azure Management Certificate • Cloud Management Gateway Certificate • Internal root certificate • Cloud Distribution Point (optional) • Azure Management Certificate • Cloud Distribution Point Certificate • Clients • Client Authentication Certificate • CMG Connection Point • Client Authentication Certificate Certificates
  • 28.
  • 29.
  • 30.
    Create CMG &CMG Connection Point Demo
  • 31.
    Configuring and monitoring theCloud Management Gateway
  • 32.
    • Configure MPto allow CMG traffic • Configure SUP to allow CMG traffic • CMG Connection Analyser • Cloud Management dashboard Using the CMG
  • 33.
    Configure MP andSUP CMG Analyser, Cloud Management dashboard Demo
  • 34.
    Managing clients with theCloud Management Gateway
  • 35.
    Client settings, Windows10 client, tips and tricks Demo
  • 36.
  • 37.
    Thanks to ourevent sponsors Silver Platinum #Scugbe #LLUniteBE #BEEMUG