Leveraging the Capabilities of System Center Configuration Manager 2007 R2

Analysis
Apr 2, 20104 mins

Best Practices at Successfully Rolling out SCCM

System Center Configuration Manager 2007 R2 is the latest systems management product from Microsoft.  SCCM has a long history in systems management, much of which is not necessarily well remembered by old timers in the IT industry when SCCM was known as Microsoft SMS (Systems Management Server).  SMS 2003 and the predecessors SMS 2.0 and SMS 1.3 were very complicated tools.  For organizations that simply wanted to patch and update systems, and occasionally push out a product update (like an Office 2003 update, or new version of Adobe Acrobat), SMS practically took a full time person to manage the management system.

A lot has changed in the past 7-10 years with systems management, now about 4 major editions past the old SMS days.  A number of things have been improved since the early days with SCCM now leveraging Active Directory for user and system identification, leverages BITS replication to provide background transfer of data, utilizes out of the box MSI and EXE installation packages commonly found in applications for easy software installation, and a host of automated wizards and integrated tools that make systems management a much easier task than generations in the past.

Key things that System Center Configuration Manager 2007 R2 does includes:

  • Patching and Updating Systems:  the very basics of systems management, SCCM patches and updates Microsoft and non-Microsoft applications.  SCCM uses Microsoft’s Windows Server Update Services (WSUS) to patch and update Microsoft systems and applications, as well as provides full integrated support to patch and update non-Microsoft products. Unlike WSUS where policies are set and it is “hoped” that the patch or update really gets applied, SCCM can be set to “enforce” the installation of an update including forcing a system reboot after a given period of warnings to the user.

  • Operating System Deployment:  SCCM has the ability of managing the automatic deployment of operating systems on client systems and servers, pushing out images or scripted installations, injecting drivers, and configuring the base operating system of a system

  • Application Deployment:  SCCM can take standard MSI or EXE installation packages and push out applications to systems, or an application can be custom packaged and pushed out to a system for installation

  • System Inventory:  When SCCM is set to manage a system, the system’s inventory (hardware and software) is gathered so that SCCM knows how to manage a system, but also can provide reports on software, hardware, or system inventory

  • Remote Control Support:  When a user is connected to the network, SCCM has the ability of remote controlling into the user’s session and take control to remotely support the user.

  • Desired Configuration Management (DCM):  A technology added in the past couple years is this Desired Configuration Manager, or DCM, that allows an administrator to set a configuration standard for systems, and if a system falls out of the specified configuration, it can trigger SCCM to update the system to meet the standard configuration, or can alert IT that a system is out of spec.  This is used regularly by organizations with regulatory compliance requirements where the IT department can confirm that ALL systems meet a specific security spec, or access spec, or the like, helping the organization provide auditors with information they need on the configuration of systems.

  • Internet Client:  Another relatively new technology to SCCM is the Internet Client that uses PKI certificates to identify systems, even systems that are remote from the network.  Normally a system has to be logged into the network, or VPN’d in remotely to a network in order for patches, updates, and group policies to be applied.  With the Internet Client that is based on a PKI certificate, the system is automatically identified anywhere on the Internet simply by having the system connect to any connection point on the Internet.  This allows an organization to patch, update, administer, manage, and support systems even if the user never VPNs or directly connects to the network.

All of these technologies are built in to System Center Configuration Manager 2007 R2 and is the basis of systems management in the enterprise. 

rand morimoto

Rand is a Microsoft MVP and security specialist with expertise in Office 365, Microsoft Azure, Exchange, SharePoint, SQL, Windows Server, Windows Client, System Center, and Lync. Rand has over 50 international bestselling books and speaks at conferences and conventions somewhere in the world every month. Rand is also the owner of the consulting firm Convergent Computing, which was Microsoft's Global Partner of the Year (2014) and an early adopter organization across all of the Microsoft products and services.

More from this author