How to Troubleshoot Apps for the Modern Connected Worker
SCCM on Microsoft Azure
1. System Center Configuration Manager
(SCCM) on Microsoft Azure
Mohamed Tawfik
Presales Technical Consultant
30-05-2017
2. Contents
Cloud Computing Value Proposition
Microsoft Azure
System Center Suite
System Center Configuration Manager (SCCM) on Microsoft Azure - Architecture
Microsoft Azure Demo
SCCM Setup on Microsoft Azure
SCCM Tour & Demo
Q&A
4. Cloud Computing Value Proposition
• Pay for what you use
• Quick Setup
• Safety
• Scalability
• Redundancy
• High Availability
• Reliability
• Focus on Concept
6. Microsoft Azure: Market Share
Canalys’ Senior Analyst De Leon said Microsoft’s
incredible growth was due to its ability to convert its
enormous enterprise client base into Azure
customers. Many leading enterprise vendors are
already building on Azure Stack, Microsoft’s
upcoming, on-premises private cloud solution, to offer
hybrid solutions to their customers.
https://www.canalys.com/newsroom/cloud-service-
providers%E2%80%99-battle-drives-worldwide-cloud-
infrastructure-market-42-q1-2017-0
7. Microsoft Azure: Features Highlights
• Available in 140 countries, including 40 regions
• Extend Active Directory and any other on-premises directories to Azure AD to enable single sign-on and centrally manage employee
access to Microsoft web services such as Azure, Office 365, Dynamics CRM Online, Intune, and thousands of non-Microsoft cloud
applications.
• Azure users can leverage a global network of datacenters to maintain availability in a cost-effective manner.
• CDN increases performance by caching blobs and static content of compute instances at physical nodes globally.
• Express Route connects on-premises infrastructure directly to Azure datacenters. Connections do not go over the public Internet and
improve reliability, speed, and security over typical Internet connections.
• HDInsight Big Data (based on Apache Hadoop) analytics that integrate easily with Microsoft Office.
• Stream Analytics process data streams in real-time to discover and react to trends.
• Machine Learning mine historical data with compute power to predict future trends or behavior
10. Microsoft Azure: Office 365
If you are using office 365, you are using Azure Active Directory in the
background.
HP Confidential, for HP Internal use only.
11. Microsoft Azure: HP Device Manager
Technical white paper: HPDM & Microsoft Azure Cloud Deployment Guide
ftp://ftp.hp.com/pub/hpdm/Documentation/WhitePapers/4.7/WP_Microsoft-Azure-Cloud-Deployment-Guide_HPDM-4.7-SP3.pdf
13. HP Confidential, for HP Internal use only
Component Description
Virtual Machine
Manager
Provides a management solution that lets you configure and manage virtualization hosts, networking, and
storage resources. It allows you to create and deploy virtual machines and services to private clouds.
Configuration
Manager
Manages your PCs and servers, keeps software up-to-date, sets configuration and security policies, and
monitors system status while giving your customers access to preferred applications from the devices they
choose.
Operations Manager Provides infrastructure monitoring that helps ensure the predictable performance and availability of vital
applications. It can monitor your datacenter and cloud, both private and public.
Orchestrator and
Service Management
Automation
Provides a workflow management solution for datacenters. It lets you automate the creation, monitoring,
and deployment of resources in your environment.
Service Manager Delivers an integrated platform for automating and adapting your IT service management best practices. It
provides processes for incident and problem resolution, change control, and asset lifecycle management.
Data Protection
Management
Enables data protection and recovery for your servers, including SQL Server, Exchange Server, SharePoint,
virtual servers, and file servers. It provides support for Windows laptops and desktops.
System Center Suite: Components
Delivers unified management across on-premises, service provider, and Microsoft Azure environments.
14. Component Description
Azure Pack Allows you to build a private cloud and run select Azure workloads on-premises using Azure Pack. It is
built on Windows Server and System Center.
Windows Intune Manages PCs and mobile devices from the cloud, which enables people to use a variety of devices to
access
corporate applications and data. Windows Intune is available as a stand-alone cloud service or with
System Center Configuration Manager on-premises.
System Center Suite: Related Services
Delivers unified management across on-premises, service provider, and Microsoft Azure
environments.
20. SCCM Setup
• Setup the basic architecture as shown in a previous slide and using the following test lab guides:
Test Lab Guide: Base Configuration https://www.microsoft.com/en-us/download/details.aspx?id=6815
Test Lab Guide: Install SQL Server 2012 Enterprise https://www.microsoft.com/en-us/download/details.aspx?id=29572
Test Lab Guide: System Center 2012 Configuration Manager https://www.microsoft.com/en-us/download/details.aspx?id=30443
21. SCCM Setup on Azure: Notes
• DHCP service will be provided by the Azure virtual network.
• Configure the VM’s network adapter from Azure portal and not from Windows.
• The Azure Load Balancer will act as a router (EDGE1) which will have a front public IP (52.174.180.65) that is routable and accessed
from internet and a backend pool of virtual machines (behind NAT) that are mapped to custom ports to allow an RDP access to them.
• By default any virtual machine on Azure has access to internet.
• Make sure that the CRL distribution point on the SQL server is accessible by the AD CS server using HTTPS binding and that each
computer in the domain auto-enrolled to the PKI and is automatically receiving a certificate.
• Important! Make sure that SQL server service accounts (CORPSQLAgent & CORPSQLDatabase) are correctly configured and that
each service account has been correctly assigned a Service Principal Name (SPN) for Kerberos authentication.
• Make sure that SQL reporting services is correctly configured by check the Web service & Web portal URLs from the reporting services
configuration manager.
22. SCCM Setup: Notes
• You can either create a Point-to-Site VPN, a Vnet-to-Vnet VPN, or a site-to-site VPN.
• Point-to-Site VPN is used to connect a single onsite PC to Azure network and it requires a self signed certificate or an enterprise
certificate.
• Site-to-Site VPN is used to connect your on-premise network with Azure, it is based on IPSec and it requires a Microsoft validated VPN
device: https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpn-devices. You can also use Microsoft Windows
server built-in Routing and Remote Access Service (RRAS) as an option.
• Vnet-to-Vnet VPN is used two connect two virtual networks on Azure and it is based on a Public Shared Key (PSK). In this Demo a Vnet-
to-Vnet VPN is created between two virtual networks on in West Europe and the other is in North Europe.
• SQL Server acts as a site database server and a reporting service point as well that provides integration with SQL server Reporting
Services to create and manage reports for Configuration Manager.
• Windows Server Update Service (WSUS) acts as an upstream server for SCCM and it synchronizes directly with Microsoft Updates.
23. SCCM Setup: Notes
• Track any background communication issue using the Configuration Manager Tracer Log Tool (C:Program FilesMicrosoft
Configuration ManagertoolsCMTrace.exe.
31. SCCM Tour & Demo
select
SMS_R_SYSTEM.ResourceID,SMS_R_SYSTEM.ResourceType,SMS_R_SYSTEM.Na
me,SMS_R_SYSTEM.SMSUniqueIdentifier,SMS_R_SYSTEM.ResourceDomainORWor
kgroup,SMS_R_SYSTEM.Client from SMS_R_System where
SMS_R_System.OperatingSystemNameandVersion like "%Server 6.1%" or
SMS_R_System.OperatingSystemNameandVersion like "%Server 6.1%" or
SMS_R_System.OperatingSystemNameandVersion like "Microsoft Windows NT Server
6.1" or OperatingSystemNameAndVersion like "Microsoft Windows NT%Server 6.0%"
What is hybrid MDM with Configuration Manager?
Hybrid MDM is a solution that uses Intune as the delivery channel for policies, profiles, and applications to devices but uses Configuration Manager on-premises infrastructure to store and administer content and manage the devices. You may choose hybrid MDM if you already have a significant investment in Configuration Manager and want to extend it to manage mobile devices. A hybrid implementation gives you “single pane of glass” control, which means you can use the same on-premises infrastructure and administrative console to manage mobile devices with Intune as well as PCs and servers with the traditional Configuration Manager client.
https://docs.microsoft.com/en-us/sccm/mdm/understand/choose-between-standalone-intune-and-hybrid-mobile-device-management