Configuration Manager 2007 R2 Implementation and Administration Best Practices

Analysis
Apr 5, 20108 mins

Things to Consider When Rolling out System Center ConfigMgr 2007 R2

This posting is 1 of a monthlong series of postings on the Microsoft System Center family of products. This is an excerpt from my book “System Center Enterprise Unleashed” with more postings on the System Center family of products up at http://www.networkworld.com/community/morimoto

The following are best practices in Implementing and Administratering ConfigMgr 2007 R2:https://support.microsoft.com/kb/968872.

► It is important to fully understand the architectural design before Configuration Manager 2007 R2 server infrastructure servers and roles are deployed.

► If communication issues are a problem, make sure the settings on the local firewall have been configured correctly. For troubleshooting purposes, disable the local firewall temporarily.

► Status messages will still be sent to the Fallback Status Point, even if the client system has become orphaned due to certificate configuration issues. It is important to deploy the Fallback Status Point before deploying clients.

► Do not move domain controllers from the default OU. Moving domain controllers out of the default Domain Controllers OU is not supported. When an Enterprise Root CA is deployed, all domain controllers automatically receive a Domain Controller certificate. This certificate can be used for both client and server authentication.

► Provisioning certificates with unnecessary OIDs is not recommended. Only provision the minimum requirements needed by the client to communicate with Configuration Manager.

► The Windows Server 2008 Enterprise certificate option is not compatible with System Center Configuration Manager 2007 R2 with Service Pack 2. Choosing Windows Server 2008 Enterprise results in a version 3 template. To create a version 2 template, select Windows Server 2003 Enterprise.

► When a computer object is added to a group, it can take a long time for the setting to take effect. This is because the Kerberos ticket takes seven days to renew. The renewal time is governed by the Maximum Lifetime for User Ticket Renewal setting located in the Default Domain Policy GPO. It is not recommended to change this setting. Instead, restart the computer to refresh the Kerberos ticket.

► Make sure the subject name of the Site Servers’ Document Signing certificate is set to: The site code of this site server is . The represents the site code that will be entered during the Configuration Manager implementation.

► Until the Windows Server 2008 R2 managed service accounts are supported, use domain user accounts with limited access to run SQL Server services.

► The RTM version of SQL server 2008 is not compatible with Windows Server 2008 R2 until the latest service pack is applied. Download and install the latest service pack to ensure compatibility.

► Make sure the SPN on the SQL service account is configured correctly; otherwise, the installation of the Configuration Manager database will fail. The failed installation needs to be removed and then tried again. This is time consuming, so it’s beneficial to get it right the first time.

► Make sure the correct SQL server ports are opened in the local Windows firewall. For additional information and a script to open SQL ports, see the following Microsoft Knowledge Base article at

► Review the ExtADSch.log file for any errors after the AD schema has been extended. This log file is located in the root of drive C on the server used to execute the schema extensions. The log file should show 14 attributes and four classes have been defined.

► The WebDAV service is available natively on Windows Server 2003 and Windows Server 2008 R2 editions. For Windows Server 2008 RTM, the WebDAV component must be downloaded from Microsoft and installed separately, prior to configuring IIS.

► Do not bother with the WSUS Configuration Wizard. When the wizard opens after WSUS is successfully installed, click the Cancel button. The Configuration Manager console provides the interface to configure synchronization with Microsoft.

► Do not require all virtual directories within the WSUS Administration site to use SSL. Only the APIRemoting30, ClientWebService, DSSAuthWebService, ServerSyncWebService, and SimpleAuthWebService should require SSL.

► Make sure the WSUSUtil.exe configuressl is run after the WSUS website is configured to use SSL or the SUP communication to WSUS will fail.

► Make sure the domain name has been added to the trusted Internet Explorer zone. This will be helpful when requesting certificates and working with Configuration Manager web pages.

► Make sure the Configuration Manager Site Server Computer Account is in the local administrators group on all component servers and other Site Servers; this includes the Site Database server. The computer account of the Site Server is used to access and manage the remote server by default.

► The status summarizer for the different components is not automatically changed from red or yellow to green if the component that experienced the problem is fixed. The component summarizer simply counts the number of warning and error status messages that have been received. Manually reset the counts of status messages to clear the error or warning status.

► When configuring the parent/child relationship, be sure to add the parent Site Server computer account to the local administrators group on the child Site Server. In addition, add the child Site Servers computer account to the SMS_SiteToSiteConnection group found on the parent Site Server.

► The Trace32.exe log viewer provides a real-time view of the Configuration Manager status logs. This tool is invaluable when troubleshooting problems and understanding the environment.

► When deploying Site System roles to either the Site Server or a remote server, it is important to note the component installation wizard doesn’t actually do the installation. Check the Site Status container from within the console along with the local installation logs for details on role installation.

► A single SLP is needed for the entire Configuration Manager infrastructure; this SLP instance should be installed off the highest-level Primary Site Server, the Central Site.

► To complete the configuration of the SLP, the correct record needs to be manually added to the WINS environment. Use the NETSH command-line tool to add this record to WINS.

► Increase the number of messages allowed per hour by the FSP to support large client deployments. This prevents a backlog of status messages from occurring.

► When a Configuration Manager role is deployed, the setup routine automatically selects the drive with the largest amount of free space. To prevent Configuration Manager from selecting a particular drive, create a file called no_sms_on_drive.sms in the root of the drive on the remote system.

► Never configure overlapping boundaries. This can cause managed systems to pick use the wrong Site Server or Distribution Point. This often happens when using a combination of IP and Active Directory boundaries.

► Define the Network Access Account on the Computer Client Agent when managing non–domain members. This account is provided as a way for non–domain members to authenticate to Configuration Manager. This account should be a Domain User without additional permissions.

► The default list of “Products” supported by the Software Update Point is refreshed and updated during the synchronization process. This adds things like Windows 7 and Windows Server 2008 R2 to the Windows section. Because the entire Windows product was selected, new operating systems will automatically be enabled as they are made available on the Windows Update site and through WSUS.

► Use protected Site Servers to control access to a site. This is helpful to protect the bandwidth of a Configuration Manager managed site.

► Having an unprotected Distribution Point is often beneficial in specific scenarios. For example, a critical package deployment might supersede the risk of potential network impact. If this functionality is desired, plan to have at least one unprotected Distribution Point, typically located in a site with a large amount of bandwidth.

► It is important to make sure content is replicated to the appropriate Distribution Points throughout the hierarchy and the setting to override protected Distribution Points is used very carefully.

► Configuring Client Agents with a “simple” schedule allows the distribution of load placed on the system. Unless the server and environment have been sized to receive and process data from all clients simultaneously, care should be taken to distribute the load over a longer period.

► A client can be pushed manually from the Configuration Manager console or executed automatically when a Discovery Method is executed. It is important to disable the Automatic Push Installation option until the client is tested and the correct options set.

► All of the attributes found in the System Resource class are available through the system discovery and do not require an agent. This class can be used to create collections for systems that don’t yet have an agent.

► Review the clientadmin$ccmsetup folder on remote systems for information about the client deployment.

► Updating the membership of a collection is a two-part process: First execute the Update the Collection Membership action and then refresh the collection to show changes.

rand morimoto

Rand is a Microsoft MVP and security specialist with expertise in Office 365, Microsoft Azure, Exchange, SharePoint, SQL, Windows Server, Windows Client, System Center, and Lync. Rand has over 50 international bestselling books and speaks at conferences and conventions somewhere in the world every month. Rand is also the owner of the consulting firm Convergent Computing, which was Microsoft's Global Partner of the Year (2014) and an early adopter organization across all of the Microsoft products and services.

More from this author