techie17 Posted May 6, 2020 Posted May 6, 2020 Hi As we now have a lot of users working from home, is there a way to setup SCCM so that clients from home can connect to SCCM? Currently we are unable to deploy software or updates as they are not in school. Clients do not have VPN either so as the working from home will soon become the norm, not sure what the best approach or solution to this is. We don’t use VPN because we use OneDrive and SharePoint Thanks
kevin_lane Posted May 7, 2020 Posted May 7, 2020 I’m not sure if it can be it’s more of a management too, I would suspect that it if you have any windows 10 in your environment you could deploy always on vpn that what any internet connect devices such as a laptop would be able to successfully connect back with sccm Unless it is possible and I’m just not aware if so could someone correct me please
RobD Posted May 7, 2020 Posted May 7, 2020 You could stick in a Always On VPN and just use a device tunnel. Then use the rules on the xml to just allow access to SCCM server and AD??
techie17 Posted May 7, 2020 Author Posted May 7, 2020 Thanks. In regards to always on VPN, isnt this quite complex to install and configure?
RobD Posted May 7, 2020 Posted May 7, 2020 Its not too bad if you take your time. This is good: https://www.petenetlive.com/KB/Article/0001399
techie17 Posted May 7, 2020 Author Posted May 7, 2020 Cool thanks. I was also just reading up on creating a cloud distribution point for SCCM but again ive no idea yet on costs for the azure platform or the complexity of the setup. Do you use Always On VPN?
psydii Posted May 7, 2020 Posted May 7, 2020 Assuming single server and your DP is configured for Enhanced HTTP you can just open port 443 and 80. SCCM encrypts all sensitive data even that on port 80. https://docs.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/enhanced-http
techie17 Posted May 7, 2020 Author Posted May 7, 2020 Assuming single server and your DP is configured for Enhanced HTTP you can just open port 443 and 80. SCCM encrypts all sensitive data even that on port 80. https://docs.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/enhanced-http Is this relating the the Cloud Distribution Point or local (internal) DP?
techie17 Posted May 7, 2020 Author Posted May 7, 2020 Assuming single server and your DP is configured for Enhanced HTTP you can just open port 443 and 80. SCCM encrypts all sensitive data even that on port 80. https://docs.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/enhanced-http Looking at this article, the clients need to be joined to Azure AD aswell?
techie17 Posted May 7, 2020 Author Posted May 7, 2020 Its not too bad if you take your time. This is good: https://www.petenetlive.com/KB/Article/0001399 Will Packages/updates deploy over Always On VPN?
RobD Posted May 7, 2020 Posted May 7, 2020 Yep, the clients are basically on the network. Have you seen this, SCCM over the internet https://www.systemcenterdudes.com/internet-based-client-management/
psydii Posted May 7, 2020 Posted May 7, 2020 (edited) Looking at this article, the clients need to be joined to Azure AD aswell? If you've got AzureAD Connect, I thought the default behaviour of Windows 10 was to Hybrid Join AzureAD? Given that the other solutions involve pushing out GPO settings, you are going to need a VPN of some sort. Probably a more traditional (less secure) dial on user demand type initially to get management authority back (i.e. update kerberos tickets, group policies and refresh stuff through AzureAD Connect). Edited May 7, 2020 by psydii
techie17 Posted May 7, 2020 Author Posted May 7, 2020 If you've got AzureAD Connect, I thought the default behaviour of Windows 10 was to Hybrid Join AzureAD? Given that the other solutions involve pushing out GPO settings, you are going to need a VPN of some sort. Probably a more traditional (less secure) dial on user demand type initially to get management authority back (i.e. update kerberos tickets, group policies and refresh stuff through AzureAD Connect). I think you're correct but i will check some of the computers. Just out of interest, if they are hybrid joined and a user changes their windows 10 password at home (and Azure AD password write back is enabled with the correct licensing) would the password change on the computer, Azure AD and then write the password back to AD? Sorry to digress slightly.
psydii Posted May 7, 2020 Posted May 7, 2020 That doesn't work for us. I don't believe that it is possible. It is frustrating.
techie17 Posted May 7, 2020 Author Posted May 7, 2020 That doesn't work for us. I don't believe that it is possible. It is frustrating. Thats pants!
techie17 Posted May 7, 2020 Author Posted May 7, 2020 Just out of curiosity, Does anyone know how much an Intune licence is per month either per device or per use? This for us longer term me me a better option.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now