Jump to content


anyweb

Root Admin
  • Posts

    9195
  • Joined

  • Last visited

  • Days Won

    367

Everything posted by anyweb

  1. well there is co-management, which allows your clients to be managed both from intune and configmgr, i think that's the next step for you, right now, your clients are only managed by configmgr and therefore cannot get policy from configmgr without being connected to a vpn.. or, you need internet based client management (IBCM) but that requires a lot of PKI setup in place
  2. and how have you configured your boundaries with respect to the CMG ? Starting in version 1902, you can associate a CMG with a boundary group. This configuration allows clients to default or fallback to the CMG for client communication according to boundary group relationships. This behavior is especially useful in branch office and VPN scenarios. You can direct client traffic away from expensive and slow WAN links to instead use faster services in Microsoft Azure. Note Internet-based clients don't fall into any boundary group. In Configuration Manager version 1810 and earlier, the CMG doesn't fall into any boundary group. https://docs.microsoft.com/en-us/mem/configmgr/core/clients/manage/cmg/plan-cloud-management-gateway
  3. what does distmgr.log tell you ?
  4. and what application are you trying to run exactly ? and what version of windows 10 is it ?
  5. what command line did you use to install the portals ? if you specified -SqlInstanceName MSSQLSERVER then this error is expected... if you are using the default instance then leave out that switch
  6. i'd do an in-place upgrade, you'll need to create a detailed plan of action though and test it in a lab first.
  7. what does the C:\Windows\Temp\TriggerBitLocker.log tell you ? I haven't tested the second scenario,
  8. yes you can go ahead and remove them from the System Management contiainer, they won't return unless something is actually publishing them there
  9. i'll try and update the script/blogpost so others don't have to have this problem, thanks for the update
  10. point the gpos in an ou that has computers that you intend to manage in the new mbam environment but why do it that way, why not go with the new Bitlocker Management in ConfigMgr or use Bitlocker Management in Intune ?
  11. it's actually called Microsoft Endpoint Configuration Manager now, and why don't you do it this way - it works !
  12. anyweb

    OWN website for PKI

    good question ! the 'website' is only a DNS entry in some web registrar to link back to your webserver Virtual Machine, in other words, it's just a pointer, that's all you need, so if you have any control over DNS for a website then you can fix this easily if you look at Step 5 in Part 3 it shows you how that is done for GoDaddy (for example) so let's imagine that you own a website address called www.mywebsite.com you login to the website provider and configure a new DNS entry such as pki.mywebsite.com and point the IP address to the Internet facing IP address you have on your smoothwalls internet nic then, on the smoothwall, you forward port 80 requests to the local IP address of your webserver virtual machine, that will solve it if you don't have access to any web registrar or website, then you could do a hack, and modify the local HOSTS file on the issuingca and maybe some other vm's to point pki.mywebsite.com to the local ip address of your webserver Virtual machine... cheers niall
  13. look at your pm
  14. ok ready
  15. let's resume this tomorrow it's time for bed, sorry, ping me in the morning and i'll try and help.
  16. what version of teamviewer are you using ?
  17. pm me the password
  18. setup then scroll down to network setup and set it up as green+red if you have teamviewer i can help
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.