SlideShare a Scribd company logo
CLOUD MANAGEMENT GATEWAY
Courtesy: Microsoft Corporation
SCENARIO
AD CA
Windows
Update
INTERNET-BASED CLIENT MANAGEMENT
AD CA
Windows
Update
AD CA
 Manage traditional clients that roam on the Internet
 Without additional infrastructure
 Without exposing infrastructure to the Internet
 That is easily configured through the Configuration Manager Console
 Key features continue to work on the device when not on the corporate network
 Software updates
 Hardware and software inventory
 Endpoint protection
 Client notification
 Settings
 Applications
PLAN TO SIMPLIFY
CLOUD MANAGEMENT GATEWAY
AD CA
Windows
Update
CERTIFICATES
 Management certificate
 “Credentials” between site and Azure
 Any certificate including self-signed
 Public cert uploaded to Azure, .pfx with private key imports into site
 Web Service (server authentication) certificate
 Use public certificate provider (Symantec, Thawte)
 Wild card certificate is not supported
 Root/Subordinate certificate authority
 Used by CMG for full chain validation on client PKI certificates
 Client certificate
NETWORK PORTS
 NO INBOUND PORTS REQUIRED!
Source Port Destination Use
Service Connection Point 443 Azure Deploy CMG
CMG Connection Point 443 CMG CMG channel for first VM
CMG Connection Point 10124-10140 CMG CMG channel for additional VM instances
Client 443 CMG Client channel
SCALING CMG
East US East Asia
PERFORMANCE CONSIDERATIONS
 Any Internet-roaming client in the site will use the CMG
 Reduce network latency by locating CMG, CMG Connection Point and Site Server in same
geographic region
 Client to CMG in Azure is not regional aware
 For high availability, at least two VM instances and two CMG Connection Points per site
 Scale-out by increasing VM instances, which leverages Azure load balancer in front of CMG
 CMG does round-robin communication with multiple CMG Connection Points; creating more
on-premises roles will distribute load
BEST PRACTICES AND FAQS
 Publish Certificate Revocation List (CRL) to Internet
 HTTPS is optional on-prem
 Supports Azure US Government (Fairfax)
 Unsupported features (as of 1710)
• Azure Resource Manager
• Client deployment using client push
• Automatic site assignment
• User policies
• Application catalog
• Full operating system deployment (OSD)
• Configuration Manager console
• Remote tools
• Reporting website
• Wake on LAN
• Peer cache
• On-premises Mobile Device Management
• Mac, Linux, and UNIX clients
• Task Sequence
TROUBLESHOOTING
 Deployment:
 CloudMgr.log
 CMGSetup.log
 Service health
 CMGService.log
 SMS_CLOUD_PROXYCONNECTOR.log
 Client traffic
 CMGHttpHandler.log -> CMGService.Log -> SMS_CLOUD_PROXYCONNECTOR.log
REFERENCES
CMG Setup video
 https://youtu.be/-awTBMdMHFE
Product documentation
 https://docs.microsoft.com/en-us/sccm/core/clients/manage/manage-clients-internet
Cost estimates
 https://docs.microsoft.com/en-us/sccm/core/clients/manage/plan-cloud-management-
gateway#cost-of-cloud-management-gateway
QUESTIONS?

More Related Content

PDF
Primeiros passos para estruturar uma equipe front-end
PPTX
Linkedin sunum
PDF
Introduction of CCE and DevCloud
PPTX
Cloud computing ppt.
PPTX
Cloud Management Gateway Architecture (CMG) – Modern device management
PPTX
What Is Docker? | What Is Docker And How It Works? | Docker Tutorial For Begi...
PPTX
IBM MQ Overview (IBM Message Queue)
PDF
"DevOps > CI+CD "
Primeiros passos para estruturar uma equipe front-end
Linkedin sunum
Introduction of CCE and DevCloud
Cloud computing ppt.
Cloud Management Gateway Architecture (CMG) – Modern device management
What Is Docker? | What Is Docker And How It Works? | Docker Tutorial For Begi...
IBM MQ Overview (IBM Message Queue)
"DevOps > CI+CD "

What's hot (20)

PDF
IBM MQ: Managing Workloads, Scaling and Availability with MQ Clusters
PPTX
Micro services and Containers
PDF
Introduction to CICD
PDF
Flyway _ A Database Version Management Tool
KEY
The Developer Experience
PPTX
Introduction to Terraform Enterprise
PPTX
What's New in API Connect & DataPower Gateway in 1H 2018
PDF
System Center Configuration Manager-The Most Popular System Center Component
PPTX
SCCM 2012 Presentation
PDF
The kvm virtualization way
PPTX
Splunk metrics via telegraf
PDF
Introduction to MuleSoft
PDF
Devops | CICD Pipeline
PPTX
Introduction to MuleSoft
PPTX
Build and release in code with azure devops pipelines
PDF
ServiceNow Utah Release Highlights
PDF
Github Actions and Terraform.pdf
PPTX
GitLab.pptx
PPTX
Azure Pipelines
PPTX
CloudStack Overview
IBM MQ: Managing Workloads, Scaling and Availability with MQ Clusters
Micro services and Containers
Introduction to CICD
Flyway _ A Database Version Management Tool
The Developer Experience
Introduction to Terraform Enterprise
What's New in API Connect & DataPower Gateway in 1H 2018
System Center Configuration Manager-The Most Popular System Center Component
SCCM 2012 Presentation
The kvm virtualization way
Splunk metrics via telegraf
Introduction to MuleSoft
Devops | CICD Pipeline
Introduction to MuleSoft
Build and release in code with azure devops pipelines
ServiceNow Utah Release Highlights
Github Actions and Terraform.pdf
GitLab.pptx
Azure Pipelines
CloudStack Overview
Ad

Similar to SCCM Cloud Management Gateway (20)

PPTX
Cloud Management Gateway_Implemented.pptx
PPTX
Cloud Management Gateway for SCCMZ .pptx
PDF
Llunitebe2018 configuring a cmg in config mgr cb
PPTX
SCCM Intune Windows 10 Co Management Architecture Decisions
PPTX
I am sharing 'unit 4' with youuuuuu.PPTX
PPTX
I am sharing 'unit 4' with youuuuuu.PPTX
PPTX
gkkCloudtechnologyassociate(cta)day 2
PPTX
dtechnClouologyassociatepart2
PPTX
Transforming cloud security into an advantage
PPTX
Operational Best Practices in the Cloud
PDF
Best Practices for Multi-Cloud Security and Compliance
PDF
8 Elements of Multi-Cloud Security
PDF
Right scale enterprise solution
PDF
Right scale enterprise solution
PDF
RightScale Webinar: Security and Compliance in the Cloud
PDF
Securing The Clouds with The Standard Best Practices-1.pdf
PPTX
Cloud computing arma_nnj
PDF
CCSK, cloud security framework, Indonesia
PDF
cloud session uklug
PDF
Leveraging the Cloud: Getting the more bang for your buck
Cloud Management Gateway_Implemented.pptx
Cloud Management Gateway for SCCMZ .pptx
Llunitebe2018 configuring a cmg in config mgr cb
SCCM Intune Windows 10 Co Management Architecture Decisions
I am sharing 'unit 4' with youuuuuu.PPTX
I am sharing 'unit 4' with youuuuuu.PPTX
gkkCloudtechnologyassociate(cta)day 2
dtechnClouologyassociatepart2
Transforming cloud security into an advantage
Operational Best Practices in the Cloud
Best Practices for Multi-Cloud Security and Compliance
8 Elements of Multi-Cloud Security
Right scale enterprise solution
Right scale enterprise solution
RightScale Webinar: Security and Compliance in the Cloud
Securing The Clouds with The Standard Best Practices-1.pdf
Cloud computing arma_nnj
CCSK, cloud security framework, Indonesia
cloud session uklug
Leveraging the Cloud: Getting the more bang for your buck
Ad

More from Anoop Nair (11)

PPTX
End to End Guide Windows AutoPilot Process via Intune
PPTX
Disaster Recovery using Azure Services
PPTX
Modern Device Management Intune Policies vs Group Policies
PPTX
SCCM CDP Cloud Distribution Point and Cloud Manage Gateway Troubleshooting Tips
PPTX
Azure Automation by Deepak Dhami
PPTX
Design & Secure Your Cloud Infrastructure
PPTX
Azure AD Presentation - @ BITPro - Ajay
PPTX
SCCM ConfigMgr Intune Architecture Decision Maker
PPTX
How to start Learning Microsoft Intune
PPTX
Windows 10 Autopilot #BITPro User Group Event
PPTX
Bangalore IT Pro Full Day Event on Intune and SCCM
End to End Guide Windows AutoPilot Process via Intune
Disaster Recovery using Azure Services
Modern Device Management Intune Policies vs Group Policies
SCCM CDP Cloud Distribution Point and Cloud Manage Gateway Troubleshooting Tips
Azure Automation by Deepak Dhami
Design & Secure Your Cloud Infrastructure
Azure AD Presentation - @ BITPro - Ajay
SCCM ConfigMgr Intune Architecture Decision Maker
How to start Learning Microsoft Intune
Windows 10 Autopilot #BITPro User Group Event
Bangalore IT Pro Full Day Event on Intune and SCCM

Recently uploaded (20)

PDF
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
PDF
Advanced Soft Computing BINUS July 2025.pdf
PDF
Modernizing your data center with Dell and AMD
PDF
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
PPTX
Big Data Technologies - Introduction.pptx
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Electronic commerce courselecture one. Pdf
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
DOCX
The AUB Centre for AI in Media Proposal.docx
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Empathic Computing: Creating Shared Understanding
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
Advanced Soft Computing BINUS July 2025.pdf
Modernizing your data center with Dell and AMD
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
Big Data Technologies - Introduction.pptx
Understanding_Digital_Forensics_Presentation.pptx
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
MYSQL Presentation for SQL database connectivity
Dropbox Q2 2025 Financial Results & Investor Presentation
Unlocking AI with Model Context Protocol (MCP)
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Electronic commerce courselecture one. Pdf
CIFDAQ's Market Insight: SEC Turns Pro Crypto
The AUB Centre for AI in Media Proposal.docx
“AI and Expert System Decision Support & Business Intelligence Systems”
Empathic Computing: Creating Shared Understanding
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf

SCCM Cloud Management Gateway

  • 1. CLOUD MANAGEMENT GATEWAY Courtesy: Microsoft Corporation
  • 3. INTERNET-BASED CLIENT MANAGEMENT AD CA Windows Update AD CA
  • 4.  Manage traditional clients that roam on the Internet  Without additional infrastructure  Without exposing infrastructure to the Internet  That is easily configured through the Configuration Manager Console  Key features continue to work on the device when not on the corporate network  Software updates  Hardware and software inventory  Endpoint protection  Client notification  Settings  Applications PLAN TO SIMPLIFY
  • 5. CLOUD MANAGEMENT GATEWAY AD CA Windows Update
  • 6. CERTIFICATES  Management certificate  “Credentials” between site and Azure  Any certificate including self-signed  Public cert uploaded to Azure, .pfx with private key imports into site  Web Service (server authentication) certificate  Use public certificate provider (Symantec, Thawte)  Wild card certificate is not supported  Root/Subordinate certificate authority  Used by CMG for full chain validation on client PKI certificates  Client certificate
  • 7. NETWORK PORTS  NO INBOUND PORTS REQUIRED! Source Port Destination Use Service Connection Point 443 Azure Deploy CMG CMG Connection Point 443 CMG CMG channel for first VM CMG Connection Point 10124-10140 CMG CMG channel for additional VM instances Client 443 CMG Client channel
  • 9. PERFORMANCE CONSIDERATIONS  Any Internet-roaming client in the site will use the CMG  Reduce network latency by locating CMG, CMG Connection Point and Site Server in same geographic region  Client to CMG in Azure is not regional aware  For high availability, at least two VM instances and two CMG Connection Points per site  Scale-out by increasing VM instances, which leverages Azure load balancer in front of CMG  CMG does round-robin communication with multiple CMG Connection Points; creating more on-premises roles will distribute load
  • 10. BEST PRACTICES AND FAQS  Publish Certificate Revocation List (CRL) to Internet  HTTPS is optional on-prem  Supports Azure US Government (Fairfax)  Unsupported features (as of 1710) • Azure Resource Manager • Client deployment using client push • Automatic site assignment • User policies • Application catalog • Full operating system deployment (OSD) • Configuration Manager console • Remote tools • Reporting website • Wake on LAN • Peer cache • On-premises Mobile Device Management • Mac, Linux, and UNIX clients • Task Sequence
  • 11. TROUBLESHOOTING  Deployment:  CloudMgr.log  CMGSetup.log  Service health  CMGService.log  SMS_CLOUD_PROXYCONNECTOR.log  Client traffic  CMGHttpHandler.log -> CMGService.Log -> SMS_CLOUD_PROXYCONNECTOR.log
  • 12. REFERENCES CMG Setup video  https://youtu.be/-awTBMdMHFE Product documentation  https://docs.microsoft.com/en-us/sccm/core/clients/manage/manage-clients-internet Cost estimates  https://docs.microsoft.com/en-us/sccm/core/clients/manage/plan-cloud-management- gateway#cost-of-cloud-management-gateway

Editor's Notes

  • #2: Both
  • #3: Aaron Traditional management with SCCM (not ready for modern management via Intune) Clients roam onto Internet (home, travel, remote office) Still need to be managed, especially software updates
  • #4: Aaron This method relies on Internet-facing site system servers to which clients communicate for management purposes. This method requires clients and site system servers to be configured for Internet-based management. Advantages: No cloud service dependency. No additional cost associated with a cloud subscription. Full control of servers and roles providing the service. Disadvantages: Require additional infrastructure investment. Overhead and operational cost of additional infrastructure. Infrastructure must be exposed to the Internet.
  • #5: Aaron
  • #6: Aaron Advantages: No additional infrastructure investment required. Does not expose on-premises infrastructure to the Internet. Cloud virtual machines that run the service are fully managed by Azure and require no maintenance. Easily set up and configured in the Configuration Manager console. Disadvantages: Cloud subscription cost. Management data sent through cloud service.
  • #7: Dune
  • #8: Aaron
  • #9: Aaron
  • #10: Dune
  • #11: Dune
  • #12: Dune
  • #13: Aaron