Jump to content

Recommended Posts

Posted

Afternoon everyone,

 

The LEA have installed a central SCCM server and are in the process of giving each school a delegated distribution point (I think that is what it is called). So far they have sorted this out for AV deployment of SCEP.

 

Now they want to do the same for MDT and WSUS - but with their servers.

 

We already have MDT and WSUS and we do not want to change, but it could be handy to integrate them into their SCCM solution. So my question is a simple one...

 

Could we use their SCCM tools to control our MDT and WSUS? Can our servers be mapped to our area of control?

 

Cheers

 

Gareth

Posted

Hi Gareth,

 

SCCM has its own integrated version of WSUS and MDT/deployment so wouldn't need your two servers and they would probably would find it harder to integrate with your two servers.

However, if you are able to liaise with LEA you ask them to give you certain access to the management point (if you're lucky enough to get a LEA to do this). They can give you access to change just your 'area' of the SCCM environment. Thus allowing you to create and amend MDT on their system and only affect your distribution point.

  • Thanks 1
Posted
So currently are you using MDT not intergated with SCCM? Is WSUS standalone as well? As the LEA has been able to deploy the SCCM client they can re-image or push out applications. If you've got a solution that's working it seems risky to put that power in the LEAs hands.
Posted
Hi Gareth,

SCCM has its own integrated version of WSUS and MDT/deployment so wouldn't need your two servers and they would probably would find it harder to integrate with your two servers.

However, if you are able to liaise with LEA you ask them to give you certain access to the management point (if you're lucky enough to get a LEA to do this). They can give you access to change just your 'area' of the SCCM environment. Thus allowing you to create and amend MDT on their system and only affect your distribution point.

 

I could ask them to do this, but it would mean spending time setting up their side of things which would be time consuming when I've already done it. Plus their distribution point would be on our main file store (which they provide). Just seems a better idea linking things up to what we have already.

 

I've thought about asking them if I could use their license to install it on our own virtual server and run our own installation of sccm - I assume them my servers would just drop into that?

 

Gareth

Posted
Do you trust the LEA not to mistakenly reimage your whole school?

 

Well - last month they put a policy on my OU that updated our whole school. More like they do not trust us with stuff - yet we are ahead of them on so many things. Annoys me how they do what they want when they want but tell us their support stops when the network enters the school.

 

Gareth

Posted
So currently are you using MDT not intergated with SCCM? Is WSUS standalone as well? As the LEA has been able to deploy the SCCM client they can re-image or push out applications. If you've got a solution that's working it seems risky to put that power in the LEAs hands.

 

That is correct. The LEA hold the AD centrally and despite asking, we were always told that SCCM couldn't be installed by us as the AD needed to be updated. I trusted that of course. So we have our own MDT server and our own WSUS server - both of which are my babies lOL. I set them up, I've configured them, I've taight myself how to use then and keep them working etc etc.

 

We have a solution that works - but isn't SCCM an improvement? Doesn't it offer more for me?

 

Gareth

Posted

@localzuk would be a good person to get input from as I believe he has a multi site sccm setup.

 

However, off the top of my head I don't think what you are proposing regarding using their installation to take control of your existing tools is possible or desirable. Sccm is installed first and then things like MDT and WSUS are integrated post install. It is important not to configure WSUS before sccm else you can get some funky results.

 

To be honest I would be extremely nervous about being part of an LA sccm hierarchy. It's not at all difficult to cause a serious amount of damage with a couple of errant clicks in sccm. Also I wouldn't like to hand over responsibility for deploying updates. Have they been tested etc?

Posted
Well - last month they put a policy on my OU that updated our whole school. More like they do not trust us with stuff - yet we are ahead of them on so many things. Annoys me how they do what they want when they want but tell us their support stops when the network enters the school.

 

Gareth

 

That is correct. The LEA hold the AD centrally and despite asking, we were always told that SCCM couldn't be installed by us as the AD needed to be updated. I trusted that of course. So we have our own MDT server and our own WSUS server - both of which are my babies lOL. I set them up, I've configured them, I've taight myself how to use then and keep them working etc etc.

 

We have a solution that works - but isn't SCCM an improvement? Doesn't it offer more for me?

 

Gareth

 

So there support stops when the network enters the school, but they control AD and SCCM. That doesn't add up. They could make a change in AD, group policy or SCCM and say oops we don't support our own screw up.

I would be extremely uncomfortable with that situation, but here AD and SCCM are my babies.

 

It is true there is an AD change needed for SCCM to work smoothly.

 

I think I'd make a long term plan to move to your own AD domain in house then move to SCCM.

 

Since the LEA has AD why don't they run a WSUS server too seams like a logical step.

Do you have control to manager your OU in AD or group policies?

 

Yes SCCM is an improvement and offers more features, but has greater complexity.

Posted
This is why RBA exsits in SCCM. Seems to be an issue of control. Do you lose it but run the risk of mistakes being across your environment?
Posted

Sounds like you need to take control over your network back off your LA. I don't see any need for LA controlled or provided services nowadays, generally they're worse than that you could do yourself or buy in from private companies, and cost more too. This was the case for us, anyway.

 

Your LA was right, you can't really install your own SCCM instance since it *does* hook into Active Directory a lot, although I think (I could be wrong) you could do it under a child domain. You won't be able to run your own WSUS server since SCCM relies on that as a core function of it's updating and compliance functionality, so the LA will manage that on your behalf.

 

I wouldn't trust an LA with SCCM access, though. There are plenty of cases of people doing dangerous things with SCCM and wiping out entire orgs.

Posted
I really wouldn't like someone external having the ability to nuke my network by accident or through malice. Having SCCM centrally is a good thing if they are actually the ones providing that support (like we are doing for our schools here), but if they aren't, then why do they need SCCM for your network?
Posted
Annoys me how they do what they want when they want but tell us their support stops when the network enters the school.

Well to be honest its one or the other if they want to go ahead with this. They can't put systems in to manage your network but then absolve themselves of blame if they do something to mess it up. And we're talking serious mess up here.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...