Showing posts with label ConfigMgr as a service. Show all posts
Showing posts with label ConfigMgr as a service. Show all posts

Wednesday, October 19, 2016

New ConfigMgr Current Branch features from 1511 till now! (part 2)

Since December 8, 2015 ConfigMgr Current Branch is Generally Available. This based on version 1511, which stands for November 2015 (MMYY). Since this release (and even before that too), there are monthly features added in Technical Preview, which are merged in public release (1602, 1606). Let's have a look at new features so far. When available this blogpost will be updated with new releases.

Microsoft did an amazing job on new ConfigMgr features for both standalone and hybrid environments. Really love the speed on new builds and update experience. Remember: When you want to go fast with Windows, you need to go fast with ConfigMgr too! :-)

New features in production so far:

[1610]
Deny previously approved application requests:
As an administrator you can deny a previously approved application request. To install this application later, users must resubmit a request. This does not uninstall the application.

Exclude clients from automatic upgrade:
When you configure settings to control how clients automatically upgrade you can now specify a collection to exclude specific clients from the upgrade. This applies to automatic upgrade as well as other methods such as software update-based upgrade. This can be used for a collection of computers that need greater care when upgrading the client.

Filter by content size in automatic deployment rules:
Use the content size filter in automatic deployment rules to prevent large software updates from automatically downloading to better support simplified Windows down-level servicing when network bandwidth is limited.

Improvements to the notification experience for high-impact task sequence and required application deployments:
Task sequence deployments that have a high-impact to the end user, for example operating system deployments, now display more intrusive notifications. However, end users can dismiss (snooze) these notifications, and control when they reappear. Any relevant client settings for notification frequency are still honored.


[1609]
Android, iOS, and Windows Additional Settings:
New settings have been added for Android, iOS, and Windows.

Boundary Group Improvements:
Improvements have been made to boundary groups to allow more granular control of fallback behavior, and greater clarity of what distribution points are used.

Deploy Office 365 apps to clients:
We have added a new Office 365 Servicing node in the Software Library where you can deploy Office 365 apps to clients.

Improvements for BIOS to UEFI conversion:
An OS deployment task sequence can now be customized with a new variable, TSUEFIDrive, so that the Restart Computer step will prepare the drive for transition to UEFI. See the documentation for additional details on the necessary customizations.

Intune Compliance Charts:
Administrators can get a quick view of overall compliance, and top reasons for non-compliance using new charts under Monitoring.

Native Connection Types for Windows 10 VPN Profiles:
You can now create Windows 10 VPN profiles with Microsoft Automatic, IKEv2, and PPTP connection types in the Configuration Manager console without using OMA-URI.

Office 365 Servicing Dashboard:
Use the Office 365 servicing dashboard to track Office 365 updates and deployments.

TouchID, ApplePay and Zoom DEP Settings:
DEP provides the ability for admins to create enrollment profiles to skip initial setup screens for new iOS devices. TouchID, ApplePay and Zoom have now been added as options to configure in the iOS enrollment profiles.

Windows 10 Upgrade Analytics:
Assess and analyze device readiness and compatibility with Windows 10 to allow smoother upgrades. This is done through integration with Windows Upgrade Analytics.

Windows Store for Business:
Windows Store for Business allows administrators to obtain applications (purchased or free) and deploy them to users in their organization.


[1608]
Application Requests from Software Center:
Users are now able to request approval for applications and view the request history for applications in the Application Details view in Software Center. The Request button in Application Details no longer redirects to the web-based Application Catalog.

Improvements to Asset Intelligence:
In the Configuration Manager 1608 Technical Preview, we have added a field to the properties for inventoried software that lets you set a parent and child relationship with other software. In the Inventoried Software list, you can view the parent of any software and also hide all child software.

New Software Indicators in Software Center:
The Software Center Applications, Updates, and Operating Systems tabs now show what software was recently added. Numbers in the navigation pane show how many new pieces of software are in each tab.

Remote Control Keyboard Translation:
In a remote control session, keys typed are now mapped by default to the sharer's keyboard when the keyboard languages do not match, so that the viewer is able to type normally. This behavior may be turned off in the Remote Control viewer Action menu.


[1607]
Customizable Branding for End-User Dialogs:
End-user dialogs that are opened from Software Center or taskbar notifications now show the same organization name, color and icon branding as Software Center. The administrator workflow for specifying branding settings remains unchanged.

Manage duplicate hardware identifiers:
Add known duplicate MAC addresses or SMBIOS IDs to be ignored hierarchy-wide for PXE boot and client registration.

Microsoft Operations Management Suite (OMS) Connector:
Sync data such as collections from ConfigMgr to OMS.

Windows 10 Edition Upgrade:
Upgrade Configuration Manager clients running Windows 10 Professional edition to Windows 10 Enterprise edition with just a product key; no reimaging required.


Part 1 of this series can be found HERE.
Will be updated with further 2016 updates!

Wednesday, October 12, 2016

New ConfigMgr Current Branch features from 1511 till now! (part 1)

Since December 8, 2015 ConfigMgr Current Branch is Generally Available. This based on version 1511, which stands for November 2015 (MMYY). Since this release (and even before that too), there are monthly features added in Technical Preview, which are merged in public release (1602, 1606). Let's have a look at new features so far. When available this blogpost will be updated with new releases.

Microsoft did an amazing job on new ConfigMgr features for both standalone and hybrid environments. Really love the speed on new builds and update experience. Remember: When you want to go fast with Windows, you need to go fast with ConfigMgr too! :-)

New features in production so far:

[1606]
Cloud Proxy Service:
The Cloud Proxy Service provides a simple way to manage ConfigMgr clients on the Internet. The service, which is deployed to Microsoft Azure and requires an Azure subscription, connects to your on-premises ConfigMgr infrastructure using a new role called the cloud proxy connector point. You use the ConfigMgr console to deploy the service and configure the supported roles to allow cloud proxy traffic. Cloud Proxy Service currently only supports the management point, distribution point, and software update point roles.
Device Categories:
You can create device categories, which can be used to automatically place devices in device collections when used in hybrid environments. Users are then required to choose a device category when they enroll a device in Intune.
Device Guard: ConfigMgr as a managed installer with manual client configuration:
Administrators can use the new Managed Installer AppLocker rules to configure clients so that ConfigMgr-deployed software is automatically trusted, but software from other sources is not. You cannot currently configure this functionality from the ConfigMgr console. Use the instructions at this blog post to manually configure client computers to use this functionality.
End users on a Windows 10 desktop managed by on-premises MDM can install an app from the Intune Company Portal:
You can deploy an app as Available Install to a user collection and the users on a Windows 10 PC managed by on-premises MDM can use the Intune Company Portal to browse, download, and install this app.
Enforcement grace period for application and software update deployments:
Give users a grace period to install required application or software updates beyond any deadlines you configured after their computers are offline for an extended period of time.
Multiple device management points available for enrolled Windows 10 Anniversary Edition devices:
On-premises Mobile Device Management (MDM) supports a new capability in Windows 10 Anniversary Edition (Redstone 1) that automatically configures an enrolled device to have more than one device management point available for use. This capability allows the device to fallback to another device management point when the one it was using is not available.
You can deploy offline-licensed applications to a Windows 10 desktop PC managed by on-premises MDM:
You can deploy an app with an offline license from the Windows Store for Business to a Windows 10 PC managed by on-premises MDM.

[1605]
Auto-Connect App List in Windows 10 VPN Profiles:
Admins can specify desktop and universal applications in Windows 10 VPN profiles that automatically establish a connection with the VPN when launched on the client. Admins can decide whether or not to limit VPN traffic to the apps in the list.
End users on a Windows 10 desktop managed by on-premises MDM can install an app from the Intune Company Portal:
You can deploy an app as Available Install to a user collection and the users on a Windows 10 PC managed by on-premises MDM can use the Intune Company Portal to browse, download, and install this app.
Improvements to the Install Software Updates task sequence step:
This release includes improvements to smsts.log to help you troubleshoot, and a new task sequence variable, SMSTSSoftwareUpdateScanTimeout, to control the timeout on the software updates scan during the Install Software Updates task sequence step.
New tabs for Updates and Operating Systems in Software Center:
Software Updates and Operating Systems now have their own respective tabs in Software Center, rather than being accessible via the categories dropdown in the Applications tab.
On-premises Health Attestation Service integration:
Collect Health Attestation information via on-premises Health Attestation Service with a few critical bug fixes from 1604 Technical Preview.
Pre-Declare Corporate Owned Devices:
You can now identify corporate-owned devices by importing their international station mobile equipment identity (IMEI) numbers. You can upload a comma-separated values (.csv) file containing device IMEI numbers or you can manually enter device information. You can also import serial numbers for iOS devices. Imported information will set ownership of the devices that enroll as “Corporate”. An Intune license is still required for each user that accesses the service. View a video walkthrough of the Pre-declare Corporate Owned Devices feature.
Remote Device Actions Experience Update:
The admin experience for wiping, resetting the passcode, remote locking, and bypassing iOS Activation Lock on mobile devices has been adjusted. The states of these actions are now part of the devices' details and properties.
Remote Full Wipe for Windows 10 desktop devices:
Support for remotely wiping and resetting Windows 10 desktop devices to factory settings.
Server groups:
Control settings for software updates in server groups, including the order and percentage of devices that can be updated at any one time. These capabilities introduce some enhancements over our pre-release "Servicing a cluster aware collection" feature, including the ability to control the order and better monitoring.
Windows 10 Enterprise Data Protection policies:
Enterprise data protection (EDP) policy settings - with this technical preview, you can create and deploy EDP policies for Windows devices running Windows 10 Insider Preview and Windows 10 Mobile Preview builds, including specifying apps, defining network boundaries, choosing the restriction modes and other EDP settings.
Windows Defender Advanced Threat Protection:
Manage Windows Defender Advanced Threat Protection policies for onboarding and offboarding Windows 10 clients to the cloud service, and view agent health in the monitoring dashboard. (Requires a Windows Defender ATP tenant in Azure.)
Windows Store for Business Integration:
ConfigMgr can manage and deploy applications purchased through the Windows Store for Business portal for both online and offline licensed apps. The 1605 Technical Preview adds the ability to create both online and offline apps with the ability to deploy offline apps to Intune and ConfigrMgr managed devices. View video walkthroughs of how to set up and deploy Windows Store for Business apps.

[1604]
Client cache size:
We added a new item to Client Settings called "Client Cache Settings". Use this to configure the client cache size as a percentage of overall disk space and megabytes.
Client Peer Cache:
A built-in ConfigMgr solution for clients to share content with other clients, directly from their local Cache with monitoring and troubleshooting capabilities.
Passport for Work:
Administrators can now deploy Passport for Work policies to domain-joined Windows 10 devices managed by the ConfigMgr client.
Policy Setting to Disable Smart Lock and other Trust Agents:
Hybrid administrators can now deploy a policy in the ConfigMgr console that disables Smart Lock and other trust agents from being used to circumvent passcode policy on devices running Android 5.0 or higher.
Software Updates Compliance Dashboard:
The Software Updates Dashboard continues our commitment to helping you keep your devices up to date with the latest security updates and Windows features. The dashboard allows you to view the current compliance status of devices in your organization and quickly analyze the data to see which devices are at risk.
Switch Software Update Point:
Administrators will be able to switch Software Update Points for clients when there are multiple SUPs available on a primary site. Administrators should use this option when clients are failing SUM scenarios due to SUP/WSUS issues on their assigned SUP. When administrators switch SUPs for a collection of clients, the selected clients will look for another SUP at the next scan interval. To try out this change go to the Asset and Compliance tab -> Device Collections -> and in the context menu of a device collection click on "Switch to Next Software Update Point".
VPN for Windows 10:
You can use 3rd party VPN providers for computers with the ConfigMgr client. These include Pulse Secure, F5 Edge, Dell SonicWall and Checkpoint.

[1603]
List View for Applications in Software Center:
In the Software Center Applications tab, users now have the option to switch between the default tile view and a new list view by clicking on the view selection icons underneath the search bar.
Install Selected Updates in Software Center:
In the new Updates tab in Software Center, click on the select mode button at the top left of the list of updates. In select mode, multiple updates may be selected and then simultaneously installed using the Install Selected button.
Content Status links in the Admin Console:
The Content Status links for objects like applications, packages, task sequences or software updates, now go directly to the related Content Status object node.
PXE Provider TFTP Window Size:
The administrator can now configure the TFTP window size (RamDiskTFTPWindowSize) via a registry setting on the PXE-enabled distribution point.
Limit access to the Clipboard in Remote Control Sessions:
You can now enable the remote tools client setting "Prompt user for shared clipboard file transfer permission" to limit access to the shared clipboard in a remote control session. When enabled, the end-user who is sharing a remote session must grant permissions to the viewer of that session before they can transfer files from the shared clipboard.

[1602]
Support for in-place upgrade of ConfigMgr Site Server's operating system:
In-place upgrade of the ConfigMgr's Site Server's operating system from Windows Server 2008 R2 to Windows Server 2012 R2 is now supported.
Sync Policy button in Software Center:
The new Sync Policy button helps you keep machine and user policies in sync. The button is available through the Software Center options tab, under Computer Maintenance.
Automatic creation of Microsoft Office mobile apps for iOS and Android:
Microsoft Office mobile apps for iOS and Android are pre-created for users using ConfigMgr integrated with Microsoft Intune.
iOS Activation Lock management:
iOS Activation Lock management capabilities include: enabling, querying for the status, retrieving bypass codes, and performing an Activation Lock bypass on corporate-owned iOS devices.

[1601]
Windows 10 Team configuration settings:
New configuration settings added and supported for Windows 10 Team when using either Intune managed (hybrid) devices, or ConfigMgr full client devices.
Windows 10 Microsoft Edge configuration settings:
Specify Windows 10 Edge settings and assign them to users or devices in their organization.
Windows 10 Conditional Access new compliance checks:
Set 3 new compliance checks: require a password to unlock an idle device, time until the device is locked, and require automatic updates with minimum classification. These policy rules are evaluated as part of overall device compliance.
Windows 10 Conditional Access with Health Attestation service:
For Intune managed devices, Windows 10 Health Attestation data can be used as part of device compliance when used with Conditional Access.
Device Compliance report:
Device Compliance report provides you the number and percentage of devices and their compliance state for each compliance policy.
Windows 10 Health Attestation service reports:
Users can view reports on Windows 10 Health Attestation data collected by Intune. Windows 10 device Health Attestation helps evaluate the vulnerability of Windows 10 desktop and mobile devices.
Kiosk mode for Samsung KNOX devices:
ConfigMgr kiosk mode allows you to lock a managed mobile device only to allow certain features. For example, you can allow a device only to run a specific managed app, or you can disable the device's volume buttons.
Client Online Status:
View the online status of devices in Assets and Compliance. New icons indicate the status of a device as online or offline.
Conditional Access for ConfigMgr Managed PCs:
To help secure Office 365 access and other services on PCs enrolled with ConfigMgr, use Conditional Access. Conditions that can be used to control access include: Workplace Join, BitLocker, Antimalware, and Software Updates.
On-Premises Exchange Default Rule Override:
Set a default on-premises Exchange rule to block mobile devices from accessing email. You can allow Intune-enrolled and compliant mobile devices to access mail. You can also choose to override the default Exchange rule to allow Intune-enrolled and compliant devices to access email, even when the default rule is set to Block or Quarantine.
iOS App Configuration:
Create and deploy iOS app configuration policies to dynamically change settings such as server name or port for iOS applications that support configuration.
Apple Volume Purchase Program:
ConfigMgr can manage and deploy applications purchased through the Apple Volume Purchase Program for Business portal.

[1512]
New antimalware policy settings:
Added settings for protection against Potentially Unwanted Applications, user control of automatic sample submission, and scanning of network drives during a full scan.
Device Health Attestation:
Users are able to view the status of Windows 10 Device Health Attestation in the ConfigMgr console, to ensure that client computers have trustworthy BIOS, TPM, and boot software.
User acceptance of Terms and Conditions:
Users who use ConfigMgr integrated with Intune (hybrid) can view which users have accepted the Terms and Conditions configured by IT and which users have not, right from the ConfigMgr console.

Will be continued in a next blogpost!

New ConfigMgr Current Branch features from 1511 till now! (part 1)

Since December 8, 2015 ConfigMgr Current Branch is Generally Available. This based on version 1511, which stands for November 2015 (MMYY). Since this release (and even before that too), there are monthly features added in Technical Preview, which are merged in public release (1602, 1606). Let's have a look at new features so far. When available this blogpost will be updated with new releases.

Really love the speed on new (Windows and ConfigMgr) builds and update experience. Remember: When you want to go fast with Windows, you need to go fast with ConfigMgr too! :-)

Microsoft did an amazing job on new ConfigMgr features for both standalone and hybrid environments. Let's have a look at new features (in production) so far:

[1606]
Cloud Proxy Service:
The Cloud Proxy Service provides a simple way to manage ConfigMgr clients on the Internet. The service, which is deployed to Microsoft Azure and requires an Azure subscription, connects to your on-premises ConfigMgr infrastructure using a new role called the cloud proxy connector point. You use the ConfigMgr console to deploy the service and configure the supported roles to allow cloud proxy traffic. Cloud Proxy Service currently only supports the management point, distribution point, and software update point roles.
Device Categories:
You can create device categories, which can be used to automatically place devices in device collections when used in hybrid environments. Users are then required to choose a device category when they enroll a device in Intune.
Device Guard: ConfigMgr as a managed installer with manual client configuration:
Administrators can use the new Managed Installer AppLocker rules to configure clients so that ConfigMgr-deployed software is automatically trusted, but software from other sources is not. You cannot currently configure this functionality from the ConfigMgr console. Use the instructions at this blog post to manually configure client computers to use this functionality.
End users on a Windows 10 desktop managed by on-premises MDM can install an app from the Intune Company Portal:
You can deploy an app as Available Install to a user collection and the users on a Windows 10 PC managed by on-premises MDM can use the Intune Company Portal to browse, download, and install this app.
Enforcement grace period for application and software update deployments:
Give users a grace period to install required application or software updates beyond any deadlines you configured after their computers are offline for an extended period of time.
Multiple device management points available for enrolled Windows 10 Anniversary Edition devices:
On-premises Mobile Device Management (MDM) supports a new capability in Windows 10 Anniversary Edition (Redstone 1) that automatically configures an enrolled device to have more than one device management point available for use. This capability allows the device to fallback to another device management point when the one it was using is not available.
You can deploy offline-licensed applications to a Windows 10 desktop PC managed by on-premises MDM:
You can deploy an app with an offline license from the Windows Store for Business to a Windows 10 PC managed by on-premises MDM.

[1605]
Auto-Connect App List in Windows 10 VPN Profiles:
Admins can specify desktop and universal applications in Windows 10 VPN profiles that automatically establish a connection with the VPN when launched on the client. Admins can decide whether or not to limit VPN traffic to the apps in the list.
End users on a Windows 10 desktop managed by on-premises MDM can install an app from the Intune Company Portal:
You can deploy an app as Available Install to a user collection and the users on a Windows 10 PC managed by on-premises MDM can use the Intune Company Portal to browse, download, and install this app.
Improvements to the Install Software Updates task sequence step:
This release includes improvements to smsts.log to help you troubleshoot, and a new task sequence variable, SMSTSSoftwareUpdateScanTimeout, to control the timeout on the software updates scan during the Install Software Updates task sequence step.
New tabs for Updates and Operating Systems in Software Center:
Software Updates and Operating Systems now have their own respective tabs in Software Center, rather than being accessible via the categories dropdown in the Applications tab.
On-premises Health Attestation Service integration:
Collect Health Attestation information via on-premises Health Attestation Service with a few critical bug fixes from 1604 Technical Preview.
Pre-Declare Corporate Owned Devices:
You can now identify corporate-owned devices by importing their international station mobile equipment identity (IMEI) numbers. You can upload a comma-separated values (.csv) file containing device IMEI numbers or you can manually enter device information. You can also import serial numbers for iOS devices. Imported information will set ownership of the devices that enroll as “Corporate”. An Intune license is still required for each user that accesses the service. View a video walkthrough of the Pre-declare Corporate Owned Devices feature.
Remote Device Actions Experience Update:
The admin experience for wiping, resetting the passcode, remote locking, and bypassing iOS Activation Lock on mobile devices has been adjusted. The states of these actions are now part of the devices' details and properties.
Remote Full Wipe for Windows 10 desktop devices:
Support for remotely wiping and resetting Windows 10 desktop devices to factory settings.
Server groups:
Control settings for software updates in server groups, including the order and percentage of devices that can be updated at any one time. These capabilities introduce some enhancements over our pre-release "Servicing a cluster aware collection" feature, including the ability to control the order and better monitoring.
Windows 10 Enterprise Data Protection policies:
Enterprise data protection (EDP) policy settings - with this technical preview, you can create and deploy EDP policies for Windows devices running Windows 10 Insider Preview and Windows 10 Mobile Preview builds, including specifying apps, defining network boundaries, choosing the restriction modes and other EDP settings.
Windows Defender Advanced Threat Protection:
Manage Windows Defender Advanced Threat Protection policies for onboarding and offboarding Windows 10 clients to the cloud service, and view agent health in the monitoring dashboard. (Requires a Windows Defender ATP tenant in Azure.)
Windows Store for Business Integration:
ConfigMgr can manage and deploy applications purchased through the Windows Store for Business portal for both online and offline licensed apps. The 1605 Technical Preview adds the ability to create both online and offline apps with the ability to deploy offline apps to Intune and ConfigrMgr managed devices. View video walkthroughs of how to set up and deploy Windows Store for Business apps.

[1604]
Client cache size:
We added a new item to Client Settings called "Client Cache Settings". Use this to configure the client cache size as a percentage of overall disk space and megabytes.
Client Peer Cache:
A built-in ConfigMgr solution for clients to share content with other clients, directly from their local Cache with monitoring and troubleshooting capabilities.
Passport for Work:
Administrators can now deploy Passport for Work policies to domain-joined Windows 10 devices managed by the ConfigMgr client.
Policy Setting to Disable Smart Lock and other Trust Agents:
Hybrid administrators can now deploy a policy in the ConfigMgr console that disables Smart Lock and other trust agents from being used to circumvent passcode policy on devices running Android 5.0 or higher.
Software Updates Compliance Dashboard:
The Software Updates Dashboard continues our commitment to helping you keep your devices up to date with the latest security updates and Windows features. The dashboard allows you to view the current compliance status of devices in your organization and quickly analyze the data to see which devices are at risk.
Switch Software Update Point:
Administrators will be able to switch Software Update Points for clients when there are multiple SUPs available on a primary site. Administrators should use this option when clients are failing SUM scenarios due to SUP/WSUS issues on their assigned SUP. When administrators switch SUPs for a collection of clients, the selected clients will look for another SUP at the next scan interval. To try out this change go to the Asset and Compliance tab -> Device Collections -> and in the context menu of a device collection click on "Switch to Next Software Update Point".
VPN for Windows 10:
You can use 3rd party VPN providers for computers with the ConfigMgr client. These include Pulse Secure, F5 Edge, Dell SonicWall and Checkpoint.

[1603]
List View for Applications in Software Center:
In the Software Center Applications tab, users now have the option to switch between the default tile view and a new list view by clicking on the view selection icons underneath the search bar.
Install Selected Updates in Software Center:
In the new Updates tab in Software Center, click on the select mode button at the top left of the list of updates. In select mode, multiple updates may be selected and then simultaneously installed using the Install Selected button.
Content Status links in the Admin Console:
The Content Status links for objects like applications, packages, task sequences or software updates, now go directly to the related Content Status object node.
PXE Provider TFTP Window Size:
The administrator can now configure the TFTP window size (RamDiskTFTPWindowSize) via a registry setting on the PXE-enabled distribution point.
Limit access to the Clipboard in Remote Control Sessions:
You can now enable the remote tools client setting "Prompt user for shared clipboard file transfer permission" to limit access to the shared clipboard in a remote control session. When enabled, the end-user who is sharing a remote session must grant permissions to the viewer of that session before they can transfer files from the shared clipboard.

[1602]
Support for in-place upgrade of ConfigMgr Site Server's operating system:
In-place upgrade of the ConfigMgr's Site Server's operating system from Windows Server 2008 R2 to Windows Server 2012 R2 is now supported.
Sync Policy button in Software Center:
The new Sync Policy button helps you keep machine and user policies in sync. The button is available through the Software Center options tab, under Computer Maintenance.
Automatic creation of Microsoft Office mobile apps for iOS and Android:
Microsoft Office mobile apps for iOS and Android are pre-created for users using ConfigMgr integrated with Microsoft Intune.
iOS Activation Lock management:
iOS Activation Lock management capabilities include: enabling, querying for the status, retrieving bypass codes, and performing an Activation Lock bypass on corporate-owned iOS devices.

[1601]
Windows 10 Team configuration settings:
New configuration settings added and supported for Windows 10 Team when using either Intune managed (hybrid) devices, or ConfigMgr full client devices.
Windows 10 Microsoft Edge configuration settings:
Specify Windows 10 Edge settings and assign them to users or devices in their organization.
Windows 10 Conditional Access new compliance checks:
Set 3 new compliance checks: require a password to unlock an idle device, time until the device is locked, and require automatic updates with minimum classification. These policy rules are evaluated as part of overall device compliance.
Windows 10 Conditional Access with Health Attestation service:
For Intune managed devices, Windows 10 Health Attestation data can be used as part of device compliance when used with Conditional Access.
Device Compliance report:
Device Compliance report provides you the number and percentage of devices and their compliance state for each compliance policy.
Windows 10 Health Attestation service reports:
Users can view reports on Windows 10 Health Attestation data collected by Intune. Windows 10 device Health Attestation helps evaluate the vulnerability of Windows 10 desktop and mobile devices.
Kiosk mode for Samsung KNOX devices:
ConfigMgr kiosk mode allows you to lock a managed mobile device only to allow certain features. For example, you can allow a device only to run a specific managed app, or you can disable the device's volume buttons.
Client Online Status:
View the online status of devices in Assets and Compliance. New icons indicate the status of a device as online or offline.
Conditional Access for ConfigMgr Managed PCs:
To help secure Office 365 access and other services on PCs enrolled with ConfigMgr, use Conditional Access. Conditions that can be used to control access include: Workplace Join, BitLocker, Antimalware, and Software Updates.
On-Premises Exchange Default Rule Override:
Set a default on-premises Exchange rule to block mobile devices from accessing email. You can allow Intune-enrolled and compliant mobile devices to access mail. You can also choose to override the default Exchange rule to allow Intune-enrolled and compliant devices to access email, even when the default rule is set to Block or Quarantine.
iOS App Configuration:
Create and deploy iOS app configuration policies to dynamically change settings such as server name or port for iOS applications that support configuration.
Apple Volume Purchase Program:
ConfigMgr can manage and deploy applications purchased through the Apple Volume Purchase Program for Business portal.

[1512]
New antimalware policy settings:
Added settings for protection against Potentially Unwanted Applications, user control of automatic sample submission, and scanning of network drives during a full scan.
Device Health Attestation:
Users are able to view the status of Windows 10 Device Health Attestation in the ConfigMgr console, to ensure that client computers have trustworthy BIOS, TPM, and boot software.
User acceptance of Terms and Conditions:
Users who use ConfigMgr integrated with Intune (hybrid) can view which users have accepted the Terms and Conditions configured by IT and which users have not, right from the ConfigMgr console.

Will be continued in a next blogpost!

Monday, November 23, 2015

Path for Upgrading ConfigMgr 2007 to ConfigMgr 2016 (as a service)

Since the ConfigMgr 2012 release (April 2012), I'm doing both implementations and 2007 migrations a lot. ConfigMgr 2012 is still the best choice for on-premises and remote device management.

With Microsoft Intune integration (part of Enterprise Mobility Suite) for mobile device and application management, you have best of both worlds. Microsoft mentions that 'No one else offers this functionality!'. Therefore ConfigMgr and EMS is the best solution for deploying and managing Windows 10 on PC's, tablets and mobile devices.

Additionally, ConfigMgr 2016 (ConfigMgr as a service, which is called just 'ConfigMgr' from now on) will support MDM-based management for Windows devices, fully on-premises, with no ConfigMgr agent required. In that case you can choose between full (with ConfigMgr agent) and MDM-based (no ConfigMgr agent) management.

But what to do if organizations are still on ConfigMgr 2007 these days?

On Microsoft TechNet there was a question about this several months ago. I did a post on Twitter today as well. The answer sounds promising: ConfigMgr 2016 does support migrating from ConfigMgr 2007 R2 SP2 and R3 SP2, which is really great news! So no need to migrate to ConfigMgr 2012 first before going to 2016. Thanks to Peter Daalmans (@pdaalmans) on this one.

ConfigMgr 2016 will be generally available in Q4 CY2015 (which is really soon!). Technical Preview 4 is released last week, which is the last technical preview before the general availability (GA) of the current branch of ConfigMgr.

Thursday, November 5, 2015

Configuration Manager (ConfigMgr) as a service won't get updated

In my LAB environment, ConfigMgr technical preview Build 1509 is installed. Problem is, it won't get updated to Build 1510. Because this functionality is the way to update ConfigMgr now and in future (ConfigMgr as a service), I did some troubleshooting. In this blogpost I give some tips and tricks to look at.

When looking in the ConfigMgr install folder have a look at these folders:
-CMUStaging & EasySetupPayload


When looking in the Logs folder have a look at these logfiles too:
-CMUpdate.log & dmpdownloader.log & hman.log


In the CMUpdate.log the following errors are found:
Set inbox to \\<CM server>\<CM site>\inboxes\cmupdate.box
*** [08001][2][Microsoft][ODBC Driver 11 for SQL Server]Named Pipes Provider: Could not open a connection to SQL Server [2].
*** [28000][18456][Microsoft][ODBC Driver 11 for SQL Server][SQL Server]Login failed for user 'NT AUTHORITY\SYSTEM'.
*** [42000][4060][Microsoft][ODBC Driver 11 for SQL Server][SQL Server]Cannot open database "<CM db>" requested by the login. The login failed.
*** [08001][2][Microsoft][ODBC Driver 11 for SQL Server]A network-related or instance-specific error has occurred while establishing a connection to SQL Server. Server is not found or not accessible. Check if instance name is correct and if SQL Server is configured to allow remote connections. For more information see SQL Server Books Online.
*** Failed to connect to the SQL Server, connection type: SMS ACCESS.
Waiting for changes to the "
\\<CM server>\<CM site>\inboxes\cmupdate.box" directories, updates will be polled in 600 seconds...

In my case the only folder seeing in EasySetupPayload folder is dcd17922-2c96-4bd7-b72d-e9159582cdf2, which is Build 1509. In manifest.log (CMUStaging folder), it's looking for db316362-77fc-46c9-9984-1baeb20615f4, which is Build 1510. So the download couldn't take place, and installation failed. I did a lot to force the download, but nothing seems to do the job.

When update tasks are not available in the ConfigMgr console (Administration > Cloud Services > Updates and Servicing) you can force it by using a SQL query:
EXEC spCMUSetUpdatePackageState N’dcd17922-2c96-4bd7-b72d-e9159582cdf2', 262146, N” (Build 1509)
EXEC spCMUSetUpdatePackageState N’db316362-77fc-46c9-9984-1baeb20615f4', 262146, N” (Build 1510)

Remember: This isn't supported, so use it at your own risk!

That didn't do the job in my LAB environment. I can choose to install Build 1510, but it won't get start downloading again.

Did the restart many times, but no files were downloaded for the new build. Another troubleshooting possible, based on the errors seen:
-Change DateTime format set to MM-DD-YYYY
-Enable Named Pipes in SQL Server Configuration Manager
-Change SQL authentication to SQL and Windows authentication
-Restart Configuration Manager Update service

Hope that anyone has a good solution to put me in the right direction! To be continued..

Update 26-7-2016: Check Microsoft TechNet for more information!

Thursday, October 29, 2015

Introducing Configuration Manager (ConfigMgr) as a service

As for today (27-1) there is a new update on the Configuration Manager Team blog. Let's have a look at the news mentioned:
 
The Future of Configuration Manager:
-During this time, we have completed the work necessary to deliver ConfigMgr more as an “as-a-Service” product.
-In terms of taxonomy for these updates, we’ll simply be referring to the ConfigMgr product as System Center Configuration Manager + year and month.
-The combination of ConfigMgr and Intune is the only solution that provides the full solution for managing all the versions of Windows, as well as all mobile devices.
-Our goals with ConfigMgr in this release cycle are all centered around finishing the work we started back in 2010 (when we were building ConfigMgr 2012) to deliver ConfigMgr as a service.
-With this work now completed, and with ConfigMgr/Intune being delivered as services, here is what we are able to do for you:
--Deliver the single-pane-of-glass for managing all devices – with immediate support across Windows, iOS and Android without you have to go through complex individual upgrades. We’ll do the work for you.


Support for Windows 10 and Microsoft Intune:
-As we announced at Microsoft Ignite with our first technical preview, we will release a new version of Configuration Manager by the end of this calendar year.
-The new System Center Configuration Manager, as it will simply be called, is designed to support the much faster pace of updates for Windows 10 and Microsoft Intune.
-System Center Configuration Manager will support Windows 10 in any flavor: Current Branch, Current Branch for Business, and Long-Term Servicing Branch.
-The fact that we are not including a calendar year in the name is a reflection of the fact that the new System Center Configuration Manager will be updated frequently.
-We plan to support each version/update for 12 months before we require that customers upgrade to the latest one to continue support.
 -If you want to deploy Windows 10 in your environment today, you should have already upgraded ConfigMgr 2012 to the latest service pack and cumulative update as many of our customers already have.

Just great we have both Windows and ConfigMgr as a service from now on. ConfigMgr is the way to go for managing all versions of Windows! Hope to implement Microsoft Intune more as well. #loveit
 
More blogposts on ConfigMgr 2016 TP3:
My experience with ConfigMgr 2016 (Technical Preview 3) so far
October Update for ConfigMgr 2016 (Technical Preview 3) available