SlideShare a Scribd company logo
8
Most read
9
Most read
10
Most read
SCCM Intune Windows 10 Co Management Architecture Decisions
ANOOP C NAIR
17+ YEARS OF EXPERIENCE IN IT
MICROSOFT MVP/VEEAM VANGUARD
@ANOOPMANNUR
WWW.ANOOPCNAIR.COM
HTTP://WWW.YOUTUBE.COM/C/ANOOPCNAIRSCCM
RAJUL
13 YEARS OF EXPERIENCE IN IT
@WANDERINGROS
@RAJULROS
AGENDA• WHAT IS CO-MANAGEMENT?
• CO-MGMT IN DETAILS
• CO-MGMT SERVER & LICENSE PRE REQUISITES
• CO-MGMT CLIENT & AZURE AD PRE REQUISITES
• CO-MGMT ENTRY POINTS
• CLOUD DP & CLOUD MGMT GATEWAY
• CMG/CDP GENERAL REQUIREMENTS
• CMG CERTS REQUIREMENTS
• CMG CONNECTIVITY FLOW
• CMG WITH EXPRESS ROUTE
• CMG SUPPORTED SCENARIOS
• DEMO
• CMG CAS SCENARIO
• CMG SCALABILITY
• C0-MGMT. BENEFITS
WHY CO-
MANAGEMENT ?
• CHANGE ?
• WORLD IS CHANGING
• DESTRUCTIVE PHASE
• WHY TROUBLING IT PROS FOR A
CHANGE ??
WHAT IS CO-MANAGEMENT?
• CO MANAGEMENT IS DEVICE MANAGEABILITY FEATURE
OF WINDOWS
• BRIDGE FROM TRADITIONAL MANAGEMENT TO
MODERN MANAGEMENT
• CO EXISTENCE OF MANAGEMENT TOOLS (INTUNE,
SCCM AND OTHER MDM??)
CO-MGMT
ARCHITECTURE
WORKLOADS
THIN LINE FUTURE
#JUST4CLICKS
CO-MGMT SERVER & LICENSE PRE REQUISITES
SCCM Intune License
SCCM 1710 or later Intune Standalone (or Mixed?) EMS or M365
Cloud Management Gateway* Azure Subscription (PaaS)*
Cloud Distribution Point
Cloud Service Configuration
* Optional
CO-MGMT CLIENT & AZURE AD PRE REQUISITES
Client Azure Active Directory or Domain
Windows 10 1709 or Later Domain Joined + AAD Registered (Hybrid AD)
Azure AD Connect
ADFS*
Azure AD automatic enrollment enabled
Azure AD Joined (Cloud)
Conditional Access Policy Changes*
* Optional
CO-MGMT ENTRY POINTS
SCCM Managed + Domain Joined  Intune Enrolment Intune Clients + Azure AD Joined  SCCM Client Installation
Windows 10 1709 or Later Windows 10 1709 or Later
SCCM Agent will automatically trigger the Intune enrolment Auto Pilot + Configuration Profiles + PowerShell Script
Firewall or Proxy Requirements (Connected to Corp LAN) CMP and CDP connectivity
AAD Registration/CMG/CDP Client Settings (Domain Joined) Intune Mobile Application to configure install SCCM client
CA, WiFi Profile, VPN Profile, Window Defender, Compliance policies Win 32 complex MSI application support /Appv Support
CLOUD DP & CLOUD MGMT GATEWAY
Cloud Distribution Point (CDP) Cloud Management Gateway (CMG)
DP on Azure Cloud Reverse Proxy on Azure?
Azure PaaS Solution Azure PaaS Solution
Azure Classic Deployment - MGMT Certs Authentication Azure Resource Manager (ARM) SCCM 1802 or later – AAD App Authentication
Azure Classic Deployment (1710 or below) - MGMT Certs Authentication
NOT Pre release Feature Anymore
CMG/CDP GENERAL REQUIREMENTS
Cloud Distribution Point (CDP) Cloud Management Gateway (CMG)
Azure Subscription admin Access (co-administrator) Azure Subscription admin Access (co-administrator)
Self Signed Management Cert At least 1 On Premise server to host CMG connection Point.
Service Certificate Certificates
Cloud Service name on public DNS Azure AD user discovery is not required (1802 onwards)
Enable Access to CDP on Client Settings Policy Clients must use IPv4
Service Connection Point to be Online Service Connection Point to be Online
CMG CERTS REQUIREMENTS
Server authentication certificate Client authentication certificate
CMG creates an HTTPS service for Internet Clients Azure AD Token for AAD joined machines
Azure Management Cert (Classic Deployment Only) Clients must trust the CMG server authentication certificate
Public Provider Certificate (Verisign/Digicert/Entrust/GoDaddy etc) or PKI Public Provider Certificate Root CA
Wildcard server authentication certificate support (1802 onwards) *.anoopcnair.com Root and Intermediate Chain of Client Certs to clients
Manual Upload – SCCM CMG installation wizard Deploy – GPO, SCCM Cert deployment, Any other delivery method
Azure management certificate is required only for classic service deployments
CMG CONNECTIVITY FLOW
AD CA
Windows
Update
Connection Point
CMG WITH EXPRESS ROUTE
CMG SUPPORTED SCENARIOS
Windows Client + Domain Join = (PKI) Windows 10 + Azure AD Join (Cloud or Hybrid) = Azure AD
Software updates & Antivirus Software updates & Antivirus
Inventory & client status Inventory & client status
Compliance settings Compliance settings
Software Deployment to the device Software Deployment to the USERS
Windows 10 in-place upgrade TS (as of version 1802) Software Deployment to the DEVICES
Windows 10 in-place upgrade TS (as of version 1802)
DEMO
Co Mgmt Settings
Co Mgmt Workload
CMG/CDP mgmt setup
Co-mgmt collection Query
CMG – CAS SCENARIO
• CMG, CMG CP, SCCM SITE SERVER IN SAME REGION
• SCCM CLIENT – CMG IS NOT REGION AWARE.
• HIGH AVAILABILITY – 2 CMG & 2 CMG CP PER REGION
CMG – SCALABILITY
1 CMG – 16 VM’s
01
1 VM – 6000
Connections
02
1 CMG CP- 4 VM
03
1 CMG (16VM’s)
= 4 CMG CP
04
CO-MGMT BENEFITS
Factory reset
01
Selective
wipe
02
Delete
devices
03
Fresh start
04
SCCM Intune Windows 10 Co Management Architecture Decisions

More Related Content

PDF
Modern Devices Management
PPTX
Get started with Windows AutoPilot Deployment
PPTX
Azure Virtual Desktop Overview.pptx
PPTX
Introduction to Microsoft Azure
PPTX
SCCM 2012 Presentation
PPTX
Microsoft Azure Technical Overview
PPTX
Modernise your Windows 10 deployment with Windows Autopilot
PPTX
Microsoft intune
Modern Devices Management
Get started with Windows AutoPilot Deployment
Azure Virtual Desktop Overview.pptx
Introduction to Microsoft Azure
SCCM 2012 Presentation
Microsoft Azure Technical Overview
Modernise your Windows 10 deployment with Windows Autopilot
Microsoft intune

What's hot (20)

PDF
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
PPTX
Introduction to Google Cloud Services / Platforms
PDF
Azure governance v4.0
PPTX
Azure Security Center- Zero to Hero
PPTX
Azure active directory
PPTX
Azure Reference Architectures
PPTX
CAF presentation 09 16-2020
PDF
Azure Service Endpoints vs. Private Links
PPT
Active Directory Training
PPTX
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
PDF
System Center Configuration Manager-The Most Popular System Center Component
PDF
Azure Security Overview
PPTX
Azure Security Overview
PDF
Introduction to Microsoft 365 Enterprise
PPTX
Windows Azure Virtual Machines
PPTX
Azure Cloud Governance
PPTX
Let's Talk About: Azure Networking
PPTX
Data Center Migration to the AWS Cloud
PDF
Understanding Azure AD
PPTX
System Center Configuration Manager 2012 Overview
Microsoft Intune - Empowering Enterprise Mobility - Presented by Atidan
Introduction to Google Cloud Services / Platforms
Azure governance v4.0
Azure Security Center- Zero to Hero
Azure active directory
Azure Reference Architectures
CAF presentation 09 16-2020
Azure Service Endpoints vs. Private Links
Active Directory Training
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
System Center Configuration Manager-The Most Popular System Center Component
Azure Security Overview
Azure Security Overview
Introduction to Microsoft 365 Enterprise
Windows Azure Virtual Machines
Azure Cloud Governance
Let's Talk About: Azure Networking
Data Center Migration to the AWS Cloud
Understanding Azure AD
System Center Configuration Manager 2012 Overview
Ad

Similar to SCCM Intune Windows 10 Co Management Architecture Decisions (20)

PDF
Llunitebe2018 configuring a cmg in config mgr cb
PPTX
SCCM CDP Cloud Distribution Point and Cloud Manage Gateway Troubleshooting Tips
PPTX
SCCM Cloud Management Gateway
PPTX
Cloud Management Gateway for SCCMZ .pptx
PDF
M14: MQ security deep dive ITC 2019
PPTX
CTU 2017 I173 - how to transform your messaging environment to a secure messa...
PPTX
VMware Certified Professional 5 - Data Center Virtualization Delta Exam
PDF
Section 3 - Technical Sales Foundations for IBM QRadar for Cloud (QRoC)V1 P10...
PDF
Course003 plugins chapters
PDF
GDG Cloud Southlake #25: Jacek Ostrowski & David Browne: Sabre's Journey to ...
PPTX
CCURE-9000_v2-90_PPT_AUG2020_SWH.pptxxxx
PPTX
Getting the Most Value from Your Aviatrix Controller & Gateways
PPTX
Configs, Configs, Everywhere! (Actually, Let's Simplify All Those Configs)
PDF
IBM MQ V8 Security
PDF
Anthos Security: modernize your security posture for cloud native applications
PDF
Smart Integration to the Cloud - Kellton Tech Webinar
PDF
VMware Workspace ONE a synergie s Microsoftem
PPTX
From Development to Deployment - Use Akamai to Facilitate Workflow Automation
PDF
Streamlining licensing migration from 3rd party systems
PPTX
FIDO Munich Seminar: Biometrics and Passkeys for In-Vehicle Apps.pptx
Llunitebe2018 configuring a cmg in config mgr cb
SCCM CDP Cloud Distribution Point and Cloud Manage Gateway Troubleshooting Tips
SCCM Cloud Management Gateway
Cloud Management Gateway for SCCMZ .pptx
M14: MQ security deep dive ITC 2019
CTU 2017 I173 - how to transform your messaging environment to a secure messa...
VMware Certified Professional 5 - Data Center Virtualization Delta Exam
Section 3 - Technical Sales Foundations for IBM QRadar for Cloud (QRoC)V1 P10...
Course003 plugins chapters
GDG Cloud Southlake #25: Jacek Ostrowski & David Browne: Sabre's Journey to ...
CCURE-9000_v2-90_PPT_AUG2020_SWH.pptxxxx
Getting the Most Value from Your Aviatrix Controller & Gateways
Configs, Configs, Everywhere! (Actually, Let's Simplify All Those Configs)
IBM MQ V8 Security
Anthos Security: modernize your security posture for cloud native applications
Smart Integration to the Cloud - Kellton Tech Webinar
VMware Workspace ONE a synergie s Microsoftem
From Development to Deployment - Use Akamai to Facilitate Workflow Automation
Streamlining licensing migration from 3rd party systems
FIDO Munich Seminar: Biometrics and Passkeys for In-Vehicle Apps.pptx
Ad

More from Anoop Nair (10)

PPTX
End to End Guide Windows AutoPilot Process via Intune
PPTX
Disaster Recovery using Azure Services
PPTX
Modern Device Management Intune Policies vs Group Policies
PPTX
Azure Automation by Deepak Dhami
PPTX
Design & Secure Your Cloud Infrastructure
PPTX
Azure AD Presentation - @ BITPro - Ajay
PPTX
SCCM ConfigMgr Intune Architecture Decision Maker
PPTX
How to start Learning Microsoft Intune
PPTX
Windows 10 Autopilot #BITPro User Group Event
PPTX
Bangalore IT Pro Full Day Event on Intune and SCCM
End to End Guide Windows AutoPilot Process via Intune
Disaster Recovery using Azure Services
Modern Device Management Intune Policies vs Group Policies
Azure Automation by Deepak Dhami
Design & Secure Your Cloud Infrastructure
Azure AD Presentation - @ BITPro - Ajay
SCCM ConfigMgr Intune Architecture Decision Maker
How to start Learning Microsoft Intune
Windows 10 Autopilot #BITPro User Group Event
Bangalore IT Pro Full Day Event on Intune and SCCM

Recently uploaded (20)

PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
Cloud computing and distributed systems.
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Approach and Philosophy of On baking technology
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Empathic Computing: Creating Shared Understanding
PDF
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...
PDF
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
PPTX
Big Data Technologies - Introduction.pptx
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
“AI and Expert System Decision Support & Business Intelligence Systems”
Cloud computing and distributed systems.
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Per capita expenditure prediction using model stacking based on satellite ima...
Approach and Philosophy of On baking technology
NewMind AI Weekly Chronicles - August'25 Week I
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Network Security Unit 5.pdf for BCA BBA.
Empathic Computing: Creating Shared Understanding
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
Big Data Technologies - Introduction.pptx
Chapter 3 Spatial Domain Image Processing.pdf
20250228 LYD VKU AI Blended-Learning.pptx
Unlocking AI with Model Context Protocol (MCP)
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf

SCCM Intune Windows 10 Co Management Architecture Decisions

  • 2. ANOOP C NAIR 17+ YEARS OF EXPERIENCE IN IT MICROSOFT MVP/VEEAM VANGUARD @ANOOPMANNUR WWW.ANOOPCNAIR.COM HTTP://WWW.YOUTUBE.COM/C/ANOOPCNAIRSCCM
  • 3. RAJUL 13 YEARS OF EXPERIENCE IN IT @WANDERINGROS @RAJULROS
  • 4. AGENDA• WHAT IS CO-MANAGEMENT? • CO-MGMT IN DETAILS • CO-MGMT SERVER & LICENSE PRE REQUISITES • CO-MGMT CLIENT & AZURE AD PRE REQUISITES • CO-MGMT ENTRY POINTS • CLOUD DP & CLOUD MGMT GATEWAY • CMG/CDP GENERAL REQUIREMENTS • CMG CERTS REQUIREMENTS • CMG CONNECTIVITY FLOW • CMG WITH EXPRESS ROUTE • CMG SUPPORTED SCENARIOS • DEMO • CMG CAS SCENARIO • CMG SCALABILITY • C0-MGMT. BENEFITS
  • 5. WHY CO- MANAGEMENT ? • CHANGE ? • WORLD IS CHANGING • DESTRUCTIVE PHASE • WHY TROUBLING IT PROS FOR A CHANGE ??
  • 6. WHAT IS CO-MANAGEMENT? • CO MANAGEMENT IS DEVICE MANAGEABILITY FEATURE OF WINDOWS • BRIDGE FROM TRADITIONAL MANAGEMENT TO MODERN MANAGEMENT • CO EXISTENCE OF MANAGEMENT TOOLS (INTUNE, SCCM AND OTHER MDM??)
  • 8. CO-MGMT SERVER & LICENSE PRE REQUISITES SCCM Intune License SCCM 1710 or later Intune Standalone (or Mixed?) EMS or M365 Cloud Management Gateway* Azure Subscription (PaaS)* Cloud Distribution Point Cloud Service Configuration * Optional
  • 9. CO-MGMT CLIENT & AZURE AD PRE REQUISITES Client Azure Active Directory or Domain Windows 10 1709 or Later Domain Joined + AAD Registered (Hybrid AD) Azure AD Connect ADFS* Azure AD automatic enrollment enabled Azure AD Joined (Cloud) Conditional Access Policy Changes* * Optional
  • 10. CO-MGMT ENTRY POINTS SCCM Managed + Domain Joined  Intune Enrolment Intune Clients + Azure AD Joined  SCCM Client Installation Windows 10 1709 or Later Windows 10 1709 or Later SCCM Agent will automatically trigger the Intune enrolment Auto Pilot + Configuration Profiles + PowerShell Script Firewall or Proxy Requirements (Connected to Corp LAN) CMP and CDP connectivity AAD Registration/CMG/CDP Client Settings (Domain Joined) Intune Mobile Application to configure install SCCM client CA, WiFi Profile, VPN Profile, Window Defender, Compliance policies Win 32 complex MSI application support /Appv Support
  • 11. CLOUD DP & CLOUD MGMT GATEWAY Cloud Distribution Point (CDP) Cloud Management Gateway (CMG) DP on Azure Cloud Reverse Proxy on Azure? Azure PaaS Solution Azure PaaS Solution Azure Classic Deployment - MGMT Certs Authentication Azure Resource Manager (ARM) SCCM 1802 or later – AAD App Authentication Azure Classic Deployment (1710 or below) - MGMT Certs Authentication NOT Pre release Feature Anymore
  • 12. CMG/CDP GENERAL REQUIREMENTS Cloud Distribution Point (CDP) Cloud Management Gateway (CMG) Azure Subscription admin Access (co-administrator) Azure Subscription admin Access (co-administrator) Self Signed Management Cert At least 1 On Premise server to host CMG connection Point. Service Certificate Certificates Cloud Service name on public DNS Azure AD user discovery is not required (1802 onwards) Enable Access to CDP on Client Settings Policy Clients must use IPv4 Service Connection Point to be Online Service Connection Point to be Online
  • 13. CMG CERTS REQUIREMENTS Server authentication certificate Client authentication certificate CMG creates an HTTPS service for Internet Clients Azure AD Token for AAD joined machines Azure Management Cert (Classic Deployment Only) Clients must trust the CMG server authentication certificate Public Provider Certificate (Verisign/Digicert/Entrust/GoDaddy etc) or PKI Public Provider Certificate Root CA Wildcard server authentication certificate support (1802 onwards) *.anoopcnair.com Root and Intermediate Chain of Client Certs to clients Manual Upload – SCCM CMG installation wizard Deploy – GPO, SCCM Cert deployment, Any other delivery method Azure management certificate is required only for classic service deployments
  • 14. CMG CONNECTIVITY FLOW AD CA Windows Update Connection Point
  • 16. CMG SUPPORTED SCENARIOS Windows Client + Domain Join = (PKI) Windows 10 + Azure AD Join (Cloud or Hybrid) = Azure AD Software updates & Antivirus Software updates & Antivirus Inventory & client status Inventory & client status Compliance settings Compliance settings Software Deployment to the device Software Deployment to the USERS Windows 10 in-place upgrade TS (as of version 1802) Software Deployment to the DEVICES Windows 10 in-place upgrade TS (as of version 1802)
  • 17. DEMO Co Mgmt Settings Co Mgmt Workload CMG/CDP mgmt setup Co-mgmt collection Query
  • 18. CMG – CAS SCENARIO • CMG, CMG CP, SCCM SITE SERVER IN SAME REGION • SCCM CLIENT – CMG IS NOT REGION AWARE. • HIGH AVAILABILITY – 2 CMG & 2 CMG CP PER REGION
  • 19. CMG – SCALABILITY 1 CMG – 16 VM’s 01 1 VM – 6000 Connections 02 1 CMG CP- 4 VM 03 1 CMG (16VM’s) = 4 CMG CP 04