SlideShare a Scribd company logo
#Scugbe
#LLUniteBE
#BEEMUG
Manage Configuration Manager
internet clients with the Cloud
Management Gateway
Gerry Hampson
Senior Consultant
Blog: gerryhampsoncm.blogspot.com
Twitter: @GerryHampson
Thanks to our event sponsors
Silver
Platinum
#Scugbe #LLUniteBE #BEEMUG
About me
@GerryHampson
Blog: gerryhampsoncm.blogspot.com
The Cloud-Management-Gateway (my version)
----------
Managing clients with the CMG
Adding the CMGIntroduction to the CMG
Agenda
Using the CMGPrerequisites for the CMG
Implementing the Cloud
Management Gateway
Planning for the Cloud
Management Gateway
Certificates for the CMG
Introduction to the
Cloud Management
Gateway
• Traditional AD joined Windows clients
• Windows 10 Azure AD joined clients
• Install the ConfigMgr client over the internet
• Software updates and endpoint protection
• Inventory and client status
• Compliance settings
• Software distribution
• Windows 10 in-place upgrade task sequence
Typical CMG scenarios
• ARM-based deployment
• Multiple instances
• Support for 96,000 clients per CMG instance
• Support for Management Point & Software Update Point
What can CMG deliver?
• DP hosted in Azure
• Optional component in CMG scenario
• Cloud DP features
• CMG and CDP co-exist
• Intranet and internet based
• Fallback content location
• Distribution Point Groups
• Content encrypted
• Scales well
• Cloud DP limitations
• PXE
• Packages that run directly
• Pre-staged/App-V streaming
• Pull DPs
Cloud Distribution Point
How does CMG
work?
Domain Contoller
Certificate Authority
INTRANET
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
INTRANET
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
Cloud Management
Gateway Connection Point
INTRANET
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
Cloud Management
Gateway Connection Point
INTRANET
Cloud Management
Gateway
Cloud DP
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
Cloud Management
Gateway Connection Point
INTRANET
Cloud Management
Gateway
Cloud DP
INTERNET
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
Cloud Management
Gateway Connection Point
INTRANET
Cloud Management
Gateway
Cloud DP
INTERNET
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
Cloud Management
Gateway Connection Point
INTRANET
Cloud Management
Gateway
Cloud DP
INTERNET
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
Cloud Management
Gateway Connection Point
INTRANET
Cloud Management
Gateway
Cloud DP
INTERNET
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
Cloud Management
Gateway Connection Point
INTRANET
Cloud Management
Gateway
Cloud DP
INTERNET
Primary Site Server
Management Point
Distribution Point
Domain Contoller
Service
Connection Point
Certificate Authority
Software Update
Point
Cloud Management
Gateway Connection Point
INTRANET
Cloud Management
Gateway
Cloud DP
INTERNET
• Virtual Machine
• Standard A2 VM
• Varies by region
• Outbound data transfer
• Data egress
• Content storage
• No cost for software updates
• CMG requires CDP for other content
CMG Cost
Prerequisites for the
Cloud Management
Gateway
• Windows clients
• ConfigMgr site (1610 or later)
• Service Connection Point (Online mode)
• Cloud Management Gateway Connection Point
• Internal Certificate Authority (autoenrollment)
• Public SSL certificate
• Externally routable domain
• Cloud Service name
• Access to DNS records
• Azure subscription
General requirements
• No inbound
• Outbound
• 443 for a single VM
• 10124 & 10125 for 2 VMs
• 10124, 10125 & 10126 for 3 VMs
• Etc up to 16 (10124 up to 10139)
Firewall Ports
Cloud Service name
Demo
Certificates for the
Cloud Management
Gateway
• Cloud Management Gateway
• Azure Management Certificate
• Cloud Management Gateway Certificate
• Internal root certificate
• Cloud Distribution Point (optional)
• Azure Management Certificate
• Cloud Distribution Point Certificate
• Clients
• Client Authentication Certificate
• CMG Connection Point
• Client Authentication Certificate
Certificates
Certificates
Demo
Adding the Cloud
Management Gateway
Create CMG & CMG Connection Point
Demo
Configuring and
monitoring the Cloud
Management Gateway
• Configure MP to allow CMG traffic
• Configure SUP to allow CMG traffic
• CMG Connection Analyser
• Cloud Management dashboard
Using the CMG
Configure MP and SUP
CMG Analyser, Cloud Management dashboard
Demo
Managing clients with
the Cloud Management
Gateway
Client settings, Windows 10 client, tips and tricks
Demo
Cloud Management
Gateway issue
Thanks to our event sponsors
Silver
Platinum
#Scugbe #LLUniteBE #BEEMUG

More Related Content

PPTX
SCCM Intune Windows 10 Co Management Architecture Decisions
PPTX
Design & Secure Your Cloud Infrastructure
PPTX
SCCM CDP Cloud Distribution Point and Cloud Manage Gateway Troubleshooting Tips
PPTX
Cloud Management Gateway Architecture (CMG) – Modern device management
PPTX
SCCM Cloud Management Gateway
PDF
Real User Monitoring: Getting Real Data from Real Users in the Real World - S...
PDF
Amazon Connect를 이용한 장애 대응도구 개발기
PDF
Complex architectures for authentication and authorization on AWS
SCCM Intune Windows 10 Co Management Architecture Decisions
Design & Secure Your Cloud Infrastructure
SCCM CDP Cloud Distribution Point and Cloud Manage Gateway Troubleshooting Tips
Cloud Management Gateway Architecture (CMG) – Modern device management
SCCM Cloud Management Gateway
Real User Monitoring: Getting Real Data from Real Users in the Real World - S...
Amazon Connect를 이용한 장애 대응도구 개발기
Complex architectures for authentication and authorization on AWS

What's hot (20)

PDF
6. DISZ - Webalkalmazások skálázhatósága a Google Cloud Platformon
PDF
Introduction to Google Cloud Platform
PDF
Gone in 4 seconds web performance optimization
PPTX
RedisConf17 - Dynomite - Making Non-distributed Databases Distributed
PPTX
Microservices in the Apache Kafka Ecosystem
PDF
Building Event Driven Services with Apache Kafka and Kafka Streams - Devoxx B...
PDF
Layer 7 Observability and Centralized Configuration with Consul Service Mesh
PPTX
What's new in NGINX Plus R9
PPTX
Spring Cloud: API gateway upgrade & configuration in the cloud
PDF
How to build 1000 microservices with Kafka and thrive
PDF
Advanced Caching Patterns used by 2000 microservices - Api World
PDF
Event Streaming with Kafka Streams and Spring Cloud Stream | Soby Chacko, VMware
PDF
Battle-tested event-driven patterns for your microservices architecture - Sca...
PPSX
SignalR With ASP.Net part1
PPT
Getting started with ASPNET Core SignalR
PDF
10 essentials steps for kafka streaming services
PPTX
Complex architectures for authentication and authorization on AWS
PDF
Building and Scaling a WebSockets Pubsub System
PPSX
Signalr with ASP.Net part2
PPTX
Real time web with SignalR
6. DISZ - Webalkalmazások skálázhatósága a Google Cloud Platformon
Introduction to Google Cloud Platform
Gone in 4 seconds web performance optimization
RedisConf17 - Dynomite - Making Non-distributed Databases Distributed
Microservices in the Apache Kafka Ecosystem
Building Event Driven Services with Apache Kafka and Kafka Streams - Devoxx B...
Layer 7 Observability and Centralized Configuration with Consul Service Mesh
What's new in NGINX Plus R9
Spring Cloud: API gateway upgrade & configuration in the cloud
How to build 1000 microservices with Kafka and thrive
Advanced Caching Patterns used by 2000 microservices - Api World
Event Streaming with Kafka Streams and Spring Cloud Stream | Soby Chacko, VMware
Battle-tested event-driven patterns for your microservices architecture - Sca...
SignalR With ASP.Net part1
Getting started with ASPNET Core SignalR
10 essentials steps for kafka streaming services
Complex architectures for authentication and authorization on AWS
Building and Scaling a WebSockets Pubsub System
Signalr with ASP.Net part2
Real time web with SignalR
Ad

Similar to Llunitebe2018 configuring a cmg in config mgr cb (14)

PPTX
Cloud Management Gateway for SCCMZ .pptx
PPTX
Cloud Management Gateway_Implemented.pptx
PPTX
Practical Guide to Cloud Management Platforms
PDF
What Every MSP Needs to Know for Cloud Success
PDF
How a CMP Can Help You Right Now
PDF
7 Common Questions About a Cloud Management Platform
PDF
Cloud Management for MSPs
PDF
Guide to managed cloud services_ Types, use cases & how to ensure success.pdf
PPTX
Configure cloud services Presentation.pptx
PPTX
Is Citrix Cloud Enterprise Ready? Best Practices to Get the Most Out of Citri...
PPTX
RapidScale Product Training
PPTX
Cloud managed services
PPTX
Mule management console
PDF
MSP_Playbook_SI_070817_v2.pdf
Cloud Management Gateway for SCCMZ .pptx
Cloud Management Gateway_Implemented.pptx
Practical Guide to Cloud Management Platforms
What Every MSP Needs to Know for Cloud Success
How a CMP Can Help You Right Now
7 Common Questions About a Cloud Management Platform
Cloud Management for MSPs
Guide to managed cloud services_ Types, use cases & how to ensure success.pdf
Configure cloud services Presentation.pptx
Is Citrix Cloud Enterprise Ready? Best Practices to Get the Most Out of Citri...
RapidScale Product Training
Cloud managed services
Mule management console
MSP_Playbook_SI_070817_v2.pdf
Ad

More from Kenny Buntinx (20)

PDF
Llunitebe2018 best of_two_worlds-manage.your.servers.the.azure.or.configmgr.way
PDF
Llunitebe2018 worst config mgr cb mistakes
PDF
Llunitebe2018 windows 10 security features
PDF
Llunitebe2018 ten practical tips to secure your corporate data with microsoft...
PDF
Llunitebe2018 rdmi in practice
PDF
Llunitebe2018 implement modern management as like brewing a beer
PDF
SCUGBE_Lowlands_Unite_2017_1E tachyon
PDF
SCUGBE_Lowlands_Unite_2017_Rest azured microsoft cloud demystified
PDF
SCUGBE_Lowlands_Unite_2017_Protecting cloud identities
PDF
SCUGBE_Lowlands_Unite_2017_Managing Windows Containers with Docker
PDF
SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss.
PDF
SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin
PDF
SCUGBE_Lowlands_Unite_2017_How to manage office 2016 on today’s clients
PDF
SCUGBE_Lowlands_Unite_2017_Achieving productivity without an on premises infr...
PPTX
ECMDay2015 - Kim Oppalfens – Microsoft System Center Configuration Manager: H...
PDF
ECMDay2015 - Nico Sienaert – Enterprise Mobility Suite – What it’s all about?
PPTX
ECMDay2015 - Kent Agerlund – Configuration Manager 2012 – A Site Review
PPTX
ECMDay2015 - Kenny Buntinx - Tim De Keukelaere - Armoring your mobile workfor...
PPTX
ECMDay2015 - Kenny Buntinx - Tim De Keukelaere - Keynote
PDF
ECMDay2015 - Peter Daalmans – Master your Mac OS X Operating System with Conf...
Llunitebe2018 best of_two_worlds-manage.your.servers.the.azure.or.configmgr.way
Llunitebe2018 worst config mgr cb mistakes
Llunitebe2018 windows 10 security features
Llunitebe2018 ten practical tips to secure your corporate data with microsoft...
Llunitebe2018 rdmi in practice
Llunitebe2018 implement modern management as like brewing a beer
SCUGBE_Lowlands_Unite_2017_1E tachyon
SCUGBE_Lowlands_Unite_2017_Rest azured microsoft cloud demystified
SCUGBE_Lowlands_Unite_2017_Protecting cloud identities
SCUGBE_Lowlands_Unite_2017_Managing Windows Containers with Docker
SCUGBE_Lowlands_Unite_2017_Servicing your new Windows workplace like a boss.
SCUGBE_Lowlands_Unite_2017_Ransomware vs. SysAdmin
SCUGBE_Lowlands_Unite_2017_How to manage office 2016 on today’s clients
SCUGBE_Lowlands_Unite_2017_Achieving productivity without an on premises infr...
ECMDay2015 - Kim Oppalfens – Microsoft System Center Configuration Manager: H...
ECMDay2015 - Nico Sienaert – Enterprise Mobility Suite – What it’s all about?
ECMDay2015 - Kent Agerlund – Configuration Manager 2012 – A Site Review
ECMDay2015 - Kenny Buntinx - Tim De Keukelaere - Armoring your mobile workfor...
ECMDay2015 - Kenny Buntinx - Tim De Keukelaere - Keynote
ECMDay2015 - Peter Daalmans – Master your Mac OS X Operating System with Conf...

Recently uploaded (20)

PDF
Advanced IT Governance
PDF
Machine learning based COVID-19 study performance prediction
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
PDF
Advanced Soft Computing BINUS July 2025.pdf
PDF
KodekX | Application Modernization Development
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
Advanced IT Governance
Machine learning based COVID-19 study performance prediction
The Rise and Fall of 3GPP – Time for a Sabbatical?
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
Advanced Soft Computing BINUS July 2025.pdf
KodekX | Application Modernization Development
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
“AI and Expert System Decision Support & Business Intelligence Systems”
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Diabetes mellitus diagnosis method based random forest with bat algorithm
Network Security Unit 5.pdf for BCA BBA.
Spectral efficient network and resource selection model in 5G networks
Chapter 3 Spatial Domain Image Processing.pdf
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Dropbox Q2 2025 Financial Results & Investor Presentation

Llunitebe2018 configuring a cmg in config mgr cb

  • 1. #Scugbe #LLUniteBE #BEEMUG Manage Configuration Manager internet clients with the Cloud Management Gateway Gerry Hampson Senior Consultant Blog: gerryhampsoncm.blogspot.com Twitter: @GerryHampson
  • 2. Thanks to our event sponsors Silver Platinum #Scugbe #LLUniteBE #BEEMUG
  • 4. The Cloud-Management-Gateway (my version) ----------
  • 5. Managing clients with the CMG Adding the CMGIntroduction to the CMG Agenda Using the CMGPrerequisites for the CMG Implementing the Cloud Management Gateway Planning for the Cloud Management Gateway Certificates for the CMG
  • 6. Introduction to the Cloud Management Gateway
  • 7. • Traditional AD joined Windows clients • Windows 10 Azure AD joined clients • Install the ConfigMgr client over the internet • Software updates and endpoint protection • Inventory and client status • Compliance settings • Software distribution • Windows 10 in-place upgrade task sequence Typical CMG scenarios
  • 8. • ARM-based deployment • Multiple instances • Support for 96,000 clients per CMG instance • Support for Management Point & Software Update Point What can CMG deliver?
  • 9. • DP hosted in Azure • Optional component in CMG scenario • Cloud DP features • CMG and CDP co-exist • Intranet and internet based • Fallback content location • Distribution Point Groups • Content encrypted • Scales well • Cloud DP limitations • PXE • Packages that run directly • Pre-staged/App-V streaming • Pull DPs Cloud Distribution Point
  • 12. Primary Site Server Management Point Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point INTRANET
  • 13. Primary Site Server Management Point Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point Cloud Management Gateway Connection Point INTRANET
  • 14. Primary Site Server Management Point Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point Cloud Management Gateway Connection Point INTRANET Cloud Management Gateway Cloud DP
  • 15. Primary Site Server Management Point Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point Cloud Management Gateway Connection Point INTRANET Cloud Management Gateway Cloud DP INTERNET
  • 16. Primary Site Server Management Point Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point Cloud Management Gateway Connection Point INTRANET Cloud Management Gateway Cloud DP INTERNET
  • 17. Primary Site Server Management Point Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point Cloud Management Gateway Connection Point INTRANET Cloud Management Gateway Cloud DP INTERNET
  • 18. Primary Site Server Management Point Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point Cloud Management Gateway Connection Point INTRANET Cloud Management Gateway Cloud DP INTERNET
  • 19. Primary Site Server Management Point Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point Cloud Management Gateway Connection Point INTRANET Cloud Management Gateway Cloud DP INTERNET
  • 20. Primary Site Server Management Point Distribution Point Domain Contoller Service Connection Point Certificate Authority Software Update Point Cloud Management Gateway Connection Point INTRANET Cloud Management Gateway Cloud DP INTERNET
  • 21. • Virtual Machine • Standard A2 VM • Varies by region • Outbound data transfer • Data egress • Content storage • No cost for software updates • CMG requires CDP for other content CMG Cost
  • 22. Prerequisites for the Cloud Management Gateway
  • 23. • Windows clients • ConfigMgr site (1610 or later) • Service Connection Point (Online mode) • Cloud Management Gateway Connection Point • Internal Certificate Authority (autoenrollment) • Public SSL certificate • Externally routable domain • Cloud Service name • Access to DNS records • Azure subscription General requirements
  • 24. • No inbound • Outbound • 443 for a single VM • 10124 & 10125 for 2 VMs • 10124, 10125 & 10126 for 3 VMs • Etc up to 16 (10124 up to 10139) Firewall Ports
  • 26. Certificates for the Cloud Management Gateway
  • 27. • Cloud Management Gateway • Azure Management Certificate • Cloud Management Gateway Certificate • Internal root certificate • Cloud Distribution Point (optional) • Azure Management Certificate • Cloud Distribution Point Certificate • Clients • Client Authentication Certificate • CMG Connection Point • Client Authentication Certificate Certificates
  • 30. Create CMG & CMG Connection Point Demo
  • 31. Configuring and monitoring the Cloud Management Gateway
  • 32. • Configure MP to allow CMG traffic • Configure SUP to allow CMG traffic • CMG Connection Analyser • Cloud Management dashboard Using the CMG
  • 33. Configure MP and SUP CMG Analyser, Cloud Management dashboard Demo
  • 34. Managing clients with the Cloud Management Gateway
  • 35. Client settings, Windows 10 client, tips and tricks Demo
  • 37. Thanks to our event sponsors Silver Platinum #Scugbe #LLUniteBE #BEEMUG