Jump to content


nicka

Non-Trusted domain policies not being retrieved

Recommended Posts

Currently I have an SCCM environment that is working fine for 2 domains, the one the server is located in and a second that has a one way trust to the first. When I try to add a third, non-trusted domain, I can add all of the servers through discovery, and they add correctly to the site (both in SCCM console and in the SCCM clients), however they do not seem to retrieve any policies.

 

Setup:

Dom1 = domain SCCM 2012 SP1 server is located in

Dom2 = one way trust of Dom1

Dom3 = no trust (problem domain)

 

The client is deployed using WSUS, and installs fine.

When I go to the client everything looks ok except for in the Action tab, where only the 2 default actions are there (Machine + User Policy Retrieval)

 

The firewall is not the issue, as I have opened up all ports in both directions (for the time being for testing).

The boundaries seem to be setup fine, as the clients are assigned to the correct site (I also assign the site through Group policy, same as I do in Dom1)

There is a client setting assigned to the collection that the clients are in, the same one that is assigned to a working collection in Dom1

 

The one thing I can think of is that a FQDN is required for Dom3, but not Dom1 or Dom2, but that does not seem to be valid, as the site is connecting properly, it is just the policies that are missing. I have gone through pretty much all of the logs on the clients, but to no avail

 

From policyevaluator.log on one of the Clients in Dom3

Evaluating policy in \\server\ROOT\ccm\Policy\Machine\RequestedConfig

Evaluation not required. No changes detected.

Raising event: instance of CCM_PolicyAgent_PolicyEvaluationComplete

P.S. sorry if I missed anything, I had a longer post written up, but accidentally refreshed the page and lost it, and I feel this one is shorter..

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.