Showing posts with label SCCM Admin. Show all posts
Showing posts with label SCCM Admin. Show all posts

April 4, 2012

SCCM Administrative Checklist

I am happy to announce that my contribution to SCCM Administration is accepted by Technet Wiki and it has been published to the Wiki Portal.

Here's the link -
http://social.technet.microsoft.com/wiki/contents/articles/8989.sccm-administrative-checklist-en-us.aspx

Your feedback are welcome.

Cheers!

April 3, 2012

SCCM 2012 Guide

An initiative and contribution from Microsoft technet wiki to all the sccm lovers/learners. It's a SCCM 2012 survival guide which helps admins to learn SCCM and get expertise in this area. I am just sharing it to the readers/admins.

http://social.technet.microsoft.com/wiki/contents/articles/8113.system-center-2012-service-manager-survival-guide-en-us.aspx

Cheers!

February 20, 2011

Mastering SCCM - Step by step guide for SCCM

Tremendous efforts have been made by anyweb (Niall Brady, founder of windows-noob). New SCCM admins can refer this step by step guide to get a thorough idea of SCCM functionalities.

Please refer to below link-
SCCM 2007 step by step Guide

Cheers.

November 29, 2010

When to use: Citrix, Med-V and App-V?

Microsoft and Citrix have introduced Virtual Desktop Infrastructure (VDI) which has below benefits for an enterprise- 
  1. Integrated Management
  2. Enhanced security and compliance
  3. Anywhere access from connected devices
  4. Increase business continuity
The Microsoft VDI Suites can especially provide tremendous benefits for customers that want to optimize desktop deployments for the following use cases-
  • Contractor devices/ third-party devices: provide managed and secured desktops to unmanaged PCs.
  • Remote Offices with excellent connectivity: centrally manage and easily deploy desktops to multiple remote and branch offices, thereby reducing IT efforts at those locations.
  • Task workers: offer choice of either session-based or virtual desktops to task workers, onsite or offshore.
  • Regulatory compliance: VDI desktops are locked behind the datacenter, thereby inherently complying with strict regulations in industries such as financial services, government, and healthcare.

I am just in review phase and can conclude main difference between Citrix XenApp, App-V and Med-V as below-
Citrix XenApp 
  1. Specially designed for session virtualization (with remote desktop services)
  2. Resolves application incompatibility with Windows upgrades
  3. User profiles are created on Citrix servers and user can easily access authorised applications.
  4. Applications need to be installed on citrix server. It does not need applications to be installed on user's machine.
  5. Users can access applications from anywhere (thru VPN) -- I don't know if it's a benefit or limitation? benefit as it supports mobility and maintains security ; limitation as it's not supported to offline mode.
  6. Integrated with AD to manage applications by groups.
  7. license cost would be applicable per user
  8. supporting limited number of sessions
  9. not applicable to desktop/application virtualization
  10. No specific reporting to licenses or total application usage by users.
  11. It requires less hardware than VDI
  12. most cost effective than VDI
Med-V
  1. Specially designed for desktop virtualization
  2. Resolves application incompatibility with Windows Vista or Windows 7. MED-V delivers applications in a virtual PC that runs a previous version of the operating system (for example: Windows XP).
  3. It helps deploy, provision, control, and support the virtual environments.
  4. It can be easily integrated with SCCM
  5. Reporting limitations as we need to check out logs from Med-V server for each machines (during multicasting OS deployment for large organization; it's difficult to track on)
  6. Centrally managed via a MED-V management server
  7. It does not work on a virtualized operating system
  8. It creates a package with a full instance of Windows
  9. It runs two environments on a single PC
  10. It provides a mechanism for automating the first-time setup of virtual machines at the endpoint, including assignment of a unique computer name, performing initial network setup, and joining the virtual machine to a corporate domain.
  11. It provides central database of client activity and events facilitating monitoring and remote troubleshooting.
  12. It provides Web browser redirection of administrator-defined domains (such as the corporate intranet or sites that require an older version of the browser) from the endpoint browser, to a browser within the virtual machine.
  13. It offers a unique method for managing an easy to support virtual desktop environment. It takes advantage of hardware independence enabled by virtualization, and maintains the exact same image across multiple endpoints. All user changes to applications or the OS are discarded once the virtual PC session ends, and the virtual machine reverts to the original image, as packaged and delivered by the administrator. This can significantly simplify management, support, and troubleshooting for virtual machines. Updates, patches, new applications, and settings changes are applied to the master virtual image, tested by the administrator, and uploaded as a new version of the virtual image to the MED-V image repository. The new version is delivered to all endpoints using Trim Transfer technology, removing the need to update each endpoint separately. 
  14. MED-V provides a first-time customization process for every deployed virtual image, where the administrator can choose to join the virtual machine to an Active Directory domain. This way, administrators can patch, update, deliver applications, and apply policies using existing tools.
  15. It supports offline mode (Offline work permissions may be limited by the administrator to a predefined period of time, after which the user must reconnect to the management server and re-authenticate. This ensures users are kept up to date with the most recent policy and permissions, and enforces expiration and de-provisioning settings on end users).
  16. It maintains high availability (MED-V client operates independently of MED-V servers. If the management server is malfunctioning or has stopped responding, all clients already running a MED-V workspace may continue working. New attempts to start a MED-V workspace will run in offline mode. Only online authentication, policy changes, and image updates are unavailable, and client events are aggregated at the client side until the server is available again).
Note: there's alot features available in Med-V which are binding me to love it and apply it to production, Thanks to Microsoft for adding values... :-)


 App-V
  1. Specially designed for Application virtualization
  2. Ability to sequence true 64-bit applications
  3. Multiple delivery options including dynamic streaming
  4. policy based application management including microsoft group policy
  5. It creates a package of single application and isolates from all other applications
  6. It resolves conflicts between applications and reduce testing
  7. It simplifies application delivery (eliminate install)
  8. Interoperable with SCCM
  9. Applications do not get installed or alter OS
  10. Applications are virtualized per instance (incl system files, registry, fonts, .ini, com/dcom objects, services, namespaces,etc)
  11. Multiple versions of same apps can be deployed together without fear of conflict
  12. Virtual apps do not permanently occupy HD space if you reset them after use
  13. some applications can not be sequenced; i.e Microsoft Office, Adobe Acrobat Standard/Pro.
  14. Some apps should not be sequenced; i.e. CS3 and AutoCAD 
  15. All workstations should have App-V clients.
Finally, I can reliable on Med-V until some more additions come to App-V.

Thanks :)

November 24, 2010

How App-V and SCCM Integration works? Architecture View

App-V and SCCM Integration Architecture

Plan for today: SCCM Administration Tips

Now onwards, I will start blogging on few SCCM Administration tips on daily basis. It would be very specific and would be helpful to all my community members.

Thanks :)

August 30, 2010

What are different Software Inventory File types- .sid, .sic, .sis?

Just get a chance to look over different types of software inventory files and listing their brief descriptions-

.SID - Software Inventory Delta (used during delta software inventory)
.SIC - Software Inventory Complete (used during Full software inventory)
.SIS - Software Inventory of application used for Symbian OS.

Enjoy!

June 16, 2010

SCCM is supported on SQL Server 2008

A clean installation of ConfigMgr RTM on SQL Server 2008 is not supported. You should upgrade instead. If you upgrade the site server database to SQL 2008 you should apply the following hotfix:
For ConfigMgr RTM - http://support.microsoft.com/kb/955229

A clean installation of ConfigMgr SP1 is supported but you should install the following hotfix:
For ConfigMgr SP1 - http://support.microsoft.com/kb/955262

February 19, 2010

What is Binary Differential Replication in SCCM?

Binary Differential Replication, sometimes known as "delta replication," is used by Configuration Manager 2007 to update package source files with a minimum of additional network traffic.

When Configuration Manager 2007 updates the source files for a package, and the source files have already been distributed, it sends the parts of the package that have changed since the last time the package was sent (originally, as an update, or as a refresh). This minimizes the network traffic between sites, especially when the package is large and the changes are relatively small. A file is considered to be changed if it has been renamed, moved, or its contents have changed.

The originating site keeps the differences between the current version of a package and the previous five versions. If a child site or distribution point has one of the previous five versions of the package, the originating site will send the appropriate changes to that site. If the child site has an older version of the package, the originating site will send the entire package.

If the originating site sends the changed files for a package but the receiving site no longer has the package, or the package has been altered at that site, the receiving site will send a status message to the originating site reporting the problem.

Note
In order for Configuration Manager 2007 to use binary differential replication, all receiving sites must first have received at least the initial version of the package. Until all receiving sites have the initial version, Configuration Manager 2007 will not use differential replication.


Care should be taken when distributing changes to a package's source files. If the path to a receiving site is closed, it is important that you not attempt to update the distribution point multiple times before the site address is again available. Each update will include the files from the previous update because the receiving sites will not yet have the previous update. As a result, the updates will include multiple redundant files, wasting network bandwidth.

Note
The processing time for large packages can take an extended period of time (20-30 minutes in some cases or even longer, depending on the size of the package). During this package compression/decompression and hashing/signature-creating process, distmgr.log might appear to be idle, even though the process is continuing.

February 17, 2010

General SMS Console access tips

If you can’t add a site server name to your SMS console try adding an entry to your machines hosts file located at C:\WINDOWS\system32\drivers\etc\hosts.

Also, it may help to add the servers’ domain to your machines list of DNS entries.

To do this on the Windows XP based computer that is running the SMS Administrator console, follow below steps:

1. Click Start, click Run, type dcomcnfg.exe, and then click OK.
2. Locate the Console root node, expand Component Services, expand Computers, and then click My Computer.
3. Right-click My Computer, and then click Properties.
4. In My Computer Properties, click the COM Security tab.
5. In Access Permission, click Edit Limits.
6. Click ANONYMOUS LOGON.
7. In Permission for ANONYMOUS LOGON, click Allow setting for Remote Access.
8. Click OK two times.
9. Restart your computer.

February 2, 2010

Daily SCCM Administrative logs: ConfigMgr'07 Inboxes to Monitor

Listed here is a list of the ConfigMgr 2007 inboxes that should be checked on a regular basis to ensure that your site(s) function as expected.

Auth\Dataldr.Box
A backlog of files can indicate problems accessing the site database.

Auth\Dataldr.Box\Process
A backlog of files can indicate problems accessing the site database.

Auth\Ddm.box\Bad_DDRs
A backlog of files can indicate a network corruption problem or a problem with the DDM

Auth\Sinv.Box
A backlog of files can indicate that the Software Inventory Processor cannot connect to the site database or that too many files were received.

Auth\Sinv.Box\Orphans
A backlog of files can indicate problems with specific clients, with management points, or with the network that could cause data corruption.

Compsumm.Box
A backlog of files can indicate that the Component Status Summarizer cannot process the volume of messages.

Dataldr.Box
A backlog of files can indicate problems accessing the Systems Management Server (SMS) database

Dataldr.Box\Badmifs
A backlog of files can indicate a bad custom MIF file or that a client computer cannot transfer the file correctly.

Ddm.Box
A backlog of files can indicate a bad DDR is preventing other DDR’s to process.

Ddm.Box\Bad_DDRs
A backlog of files can indicate a network corruption problem or a problem with the DDM

OfferSum.Box
A backlog of files can indicate a performance problem that is caused by a large number of messages.

Policypv.Box
A backlog of files in the policypv.box folder indicates that the policy provider component is not running.

Replmgr.Box\Ready
A backlog of files can indicate that the Scheduler is backlogged or is already processing files of the same priority

Schedule.Box
A backlog of files can indicate that the Sender cannot connect to or cannot transfer data to another site.

Schedule.Box\Outboxes
A backlog of .srq files indicates that the sender cannot process the number of jobs scheduled for that sender or that the sender cannot connect to or transfer data to another site.

Schedule.Box\Tosend
A backlog of files can indicate that many send requests are not completed or that the Scheduler has not yet deleted the files.

Sinv.Box
A backlog of files can indicate that the Software Inventory Processor cannot connect to the site database or that too many files were received.

Sinv.Box\BadSinv
A backlog of files can indicate problems with specific clients, with management points, or with the network, causing data corruption.

SiteStat.Box
A backlog of files can indicate a performance problem. Examine status messages for the Site System Status Summarizer for possible problems.

Statmgr.Box\Futureq
A backlog of files can indicate that some site systems' clocks are not synchronized with the site server.

Statmgr.Box\Queue
A backlog of files can indicate a problem with the Status Manager or that the component is trying to process too many messages.

Statmgr.Box\Retry
A backlog of files can indicate problems with the connection to the computer that is running SQL Server.

Statmgr.Box\Statmsgs
A backlog of files can indicate a problem with the Status Manager or that the Status Manager is trying to process too many messages

Swmproc.Box
A backlog of .sum and .sur files can indicate that the Software Metering Processor component cannot connect to the SMS database.

What is BranchCache? How SCCM supports BranchCache?

Microsoft introduced a new terminology in Windows7 and Windows Server 2008 R2 called BranchCache to reduce traffic load on wide area network called BranchCache. Network enabled with BranchCache cache data in branch and subsequent request to same data is served by cached stored in WAN branch. BranchCache optimizes traffic flow between Windows Server 2008 R2 servers and BranchCache-enabled clients; Windows Server 2008 R2 servers and computers running Windows 7 can be configured as BranchCache clients.

BranchCache operates in one of two modes:

1. Distributed Cache: In Distributed Cache mode, BranchCache-enabled clients cache copies of files downloaded from content servers across the WAN and send them directly to other clients when requested. Distributed Cache mode is especially beneficial for branch offices that do not have a local server.
2. Hosted Cache: In Hosted Cache mode, a Windows Server 2008 R2 server, known as the Hosted Cache, acts as the host for the cached content. BranchCache-enabled clients cache data that they have requested and downloaded from content servers locally and use the Hosted Cache to retrieve data that is not available from their own local cache. Clients know the identity of the Hosted Cache and retrieve data from the Hosted Cache. For data not available from the Hosted Cache, the client downloads the data from the content server and offers it for caching to the Hosted Cache. Hosted Cache mode is beneficial in organizations that want to audit access to content in the local cache, or larger branch offices that have local servers.

BranchCache Hosted and Distributed cache modes
BranchCache improves the performance of applications that use one of the following protocols:

a.Hypertext Transfer Protocol (HTTP) and Hypertext Transfer Protocol Secure (HTTPS). The protocols that Web browsers and many other applications (such as Microsoft Internet Explorer®, Microsoft Windows Media Player®, and more) use.
b.Server Message Block (SMB), including signed SMB traffic. SMB is the protocol used for shared folders on Windows networks.
c.Background Intelligent Transfer Service (BITS). BITS is used to transfer files asynchronously between a client and a server. BITS is the protocol that System Center Configuration manager (SCCM) and Windows Server Update Services (WSUS) use.

February 1, 2010

What's new in ConfigMgr'07 R3?

1. Scale & Performance Improvements: Collections in R3

a. Microsoft is focusing on evaluating new systems in R3 and will implement new collection setting called 'Fast evaluation' which populates newly discovered machines.
b. Full evaluations are still processed in the same way.
c. A new collection needs a full evaluation to show existing clients.

How it works:
- Collections are evaluated by periodically executing a query
- results are inserted into a temporary table
- this table is then merged into the master collection results table (Collection Members)
- If there is no change in results, master results table not changed
- If onlya few resources have changed, evaluation process faster due to only processing changed resources.

2. Scale & Performance Improvements: Delta AD Discovery

a. Each AD discovery query has 2 tasks:
1. Discover any changes to any users or machines, based on the query, that would likely affect targeting (default is 5 minutes)
2. Perform a periodic "full scan" to capture users and machines last logged time, ensuring active users and machines are not made obsolete.

b. On an individual query basis, select to run "discovery now" for a full scan.

3. Scale Improvements: R3 supports 3,00,000 clients when using the default settings for all ConfigMgr 2007 features.

Note: No change to other site and site role supported numbers.

4. Sharepoint based ConfigMgr dashboard
- compliance metrics related to SUM, SWD, DCM, Licensing and OSD sections for a particular time period.
- sharepoint based authentication: customize dashboards based on User Roles.

What's new in ConfigMgr'07 Service Pack 2?

SCCM 2007 SP2 supports below platforms-
-Windows 7
-Windows Server 2008 R2
-Windows Vista SP2
-Windows Server 2008 SP2

New features added to SCCM 2007 SP2 are:
1. Managed Client Support - Client can be a target for apps, inventory, updates and more.

2. Site role host control - Servers can host all site infrastructure roles.

3. Improved Client Policy Evaluation -

a. Faster Policy Processing: before SP2, policy download was queued locally for 2 minutes before processing. This 2 mins delay has been removed in SP2.
b. Most efficient software distribution configured to run at user logon:
before SP2 user policy requests were not downloaded for 2 minutes after user logon event. This caused a delay is user/group targeted advertisements.
c. A common scenario is an App-V distribution environment where user/security group targeting is used.
d. this 10 mins delay has been removed in SP2 and user/group targeted advertisements are instantly available after user logon in SP2.

4. Branch cache support:
a. Integration enables configmgr organizations to
-significantly reduce WAN traffic
-reduce transfer loads on DPs.
b. Clients that are Branch Cache enabled will transfer content from peers if available before hitting DP.

5. SP2 will also continue to deliver new support for x64 architectures including:
a. x64 support for OpsMgr'07 client agent
b. Update to OpsMgr MP for x64 OS
c. x64 performance counters
d. Remote Control support added for x64 windows XP and x64 Windows Server 2003.
e. App-V x64 Client Support.

6. Asset Intelligence Certificate Requirement Removal:
ConfgMgr'07 SP1 introduced Asset Intelligence v1.5. With SP1, Asset Intelligence could be configured to use as online synchronization for updates. With SP2, the requirement to have the certificate has been removed.
-The initial release required a certificate.
Software Assurance is not required for this functionality, including SP1.

7. Intel vPro Technology: Integration Enhancements in SP2-

a. Wireless Profile Management
b. 802.1x support
c. Non volatile memory or third party data store (3PDS)
d. Access Monitor: Audit log
e. Remote Power Management: Power State Configuratio from SCCM console.

system center power management phases:
Monitor-> Plan-> Apply-> Check-> Report (saving in power consumption and costs and environmental impact)

8. OS deployment:

a. Multiselect and delete driver catalog drivers from the SCCM console
b. task sequence UI displays package names as in the SCCM console.

9. Better feedback on AD extension success/failure.

Package sending priority in Advertisement Properties

Sending priority
The priority of this package when sent to distribution points in child sites. Packages can be sent with High, Medium, or Low priority. The default setting is Medium priority. If a package has High priority, it will be sent before packages with Medium or Low priority. If a package has Low priority, it will be sent after packages with higher priority settings.

Note: A Package will be sent in the order in which they were created in the SMS Administrator console.

January 31, 2010

Package processing thread in distmgr.log file?

When I was troubleshooting the copy package issue as mentioned in my earlier post, I got some some messages "package processing thread in queue".

I started to find out the exact meaning of this and found that the threads are used for copying packages to distribution points. If we distribute more packages at one time than the number of threads then the package will be putting on queue. The retry count is used when a copy fails.

Note: In legacy version of SMS (without SPs), the number of distribution points that could be effectively managed by a site server is small because SMS allocates a single thread per package. This results in SMS copying content to one particular distribution point, and when successful, moving to the next distribution point.
From SMS 2003 SP1, it copies content to multiple DPs in parallel. Because of this change, the failure of a single DP does not halt software distribution. This change improves both reliability and response time for package deployment, and effectively allows a single site to support a much larger number of distribution points.

The following improvements and benefits have resulted from this change:

1. Less time for package distribution to all DPs of the site
2. A single site can support more distribution points
3. Site hierarchy can be simplified to replace some secondary sites with distribution points in some of scenarios.
4. Faster Software and Patch distribution.
5.Lower hierarchy deployment costs, which results in fewer site servers

Lower maintenance costs, because it is easier to manage a distribution point than a site

January 29, 2010

Failed to hash file, Win32 error = 64: Package not copying to DP

I got this error on one of my DP while I was trying to copy package on all the DPs.
I checked the distmgr.log file from the primary server from where i was copying it to the DPs and got the error.

As a resolution step, I removed package from that DP and copy it again.

It worked well.

January 27, 2010

Why MS integrated SQL Reporting Service with Configuration Manager 2007 R2?

With Configuration Manager 2007 R2, a new site role called "Reporting Services Point" was introduced that facilitates reporting using SQL Reporting Services 2005/2008. This is accomplished via a conversion wizard that ships with Configuration Manager 2007 R2 and allows the user to convert all the Configuration Manager reports that currently exist on that site server to SQL Reporting Services based reports and deploy them to the SQL Reporting Server.

Site Role Installation and Configuration

The following outlines the overall workflow in getting a SQL Reporting Services based reporting point up and running:

1.Pre-requisites: Any machine having a valid SQL Reporting Server 2005/2008 instance running on it.
2.Run the site role wizard and install the "Reporting Services Point" on the SQL Reporting Server. The site role wizard asks for a root folder name which is basically the folder on the reporting server under which all the reports will be deployed.
3.Once the site role wizard is completed successfully, you should see the server appearing under the Reporting Services node under the Reporting node in the administration console.
4.Right click on the server and launch the "Copy Reports Wizard"
5.Run through the "Copy Reports Wizard" and select all the reports that you want to convert to SQL Reporting Services based reports.
6.The wizard will then go through the selected reports, convert them into SQL Reporting Services based reports and deploy them to the reporting server under the folder specified in step 2. above.
7.The copy reports wizard groups all the reports based on report categories creates a folder for each report category and deploys the reports under the respective report category folder.
8.Once all the reports are deployed, you can see all the report folders in the administration console and run any of the reports from any of the folders. You have the option of running the reports from within the administration console or run the reports directly from SQL Reporting Services using the SQL Report Manager (web UI). The SQL Reporting server report manager URL has the following naming convention:
For the default SQL Reporting Server instance the URL to access the report and report folders would be:

http://[ReportServer]/Reports

For named SQL Reporting server instances the URL would be:

http://[ReportServer]/Reports_[InstanceName]

Other functionalities provided within the Configuration Manager administration console

1.Report subscription wizards to create subscriptions for any of the Configuration Manager reports

2.Report authoring tools:

Model based report wizard
The Configuration Manager 2007 R2 release ships two out-of-the-box report models one for Client Health Reporting and the other for Software Updates Management. The model based report wizard facilitates users to create custom reports using these report models.

SQL Based report wizard
The SQL based report wizard facilitates SQL savvy users to specify SQL queries and generate reports off of these queries. The wizard presents the users with a list of all available Configuration Manager database views and the corresponding columns to facilitate users to formulate SQL queries more easily and make the process less prone to errors and typos.

SCCM Reports: Useful Microsoft links

Below are the Microsoft links which helps to understand SCCM reports.

Reports home page: http://technet.microsoft.com/en-us/library/bb632942.aspx

How to manage reports: http://technet.microsoft.com/en-us/library/bb632699.aspx

Technical reference for reporting: http://technet.microsoft.com/en-us/library/bb694105.aspx

January 26, 2010

What is difference between Obsolete and Inactive Clients?

I had to understand the difference as it was asked by the management and every administrator should know it.

Obsolete Clients

Obsolete client s are those that have been replaced by new ones. This usually happens during refresh OS deployments where the hardware stays the same and thus the hardware id is the same but the SMS GUID changes because the OS has been reloaded or the GUID is regenerated for another reason but the hardware remains the same.

Reasons - 
1. hard disk swapping
2. Renaming machines
3. Reimage OS
4. Reinstalling SMS/SCCM agent on the machines without proper uninstall.  

Inactive Clients

Inactive client s are those that have not been discovered recently by the heartbeat discovery. The definition of recently is defined in the delete task as a number of days. Please note that obsolete client s are also marked inactive. 

Reasons-
1. Offline machines
2. Machines having DNS issue/No name resolution
3. Machines are in inventory stock

Note: While I was trying to figure out why the some of the machines come under no status or waiting state, the above difference has helped me a lot.
I am putting some scenario here-

I have 100% healthy sms clients in the company's infrastructure and perform the activities like deleting obsolete clients, removing AD stale objects on daily basis. Inspite of this, I used to get some machines in "no status" and "waiting" category.

The reasons, I figured out, were:
offline machines/no name resolution machines were in "waiting" category and machines which were in IT stock or were inactive for a period of time, listed under "no status" category.