Korzystając z tej witryny, zgadzasz się na Polityka prywatności.
Przyjąć
EnterineEnterineEnterine
  • DOM
  • To pro
  • Tech
  • Microsoft
    • Lazur
    • Menedżer konfiguracji/SCCM
    • DPM
    • Orkiestrator
    • Hyper-V.
    • Niejawny tester Microsoft Edge
    • MSI
    • Biuro 365
    • Nieznajomy biura
    • Power bi
    • Skype'a
    • Serwer SQL
    • Zespoły
  • OKNA
    • Centrum administracyjne systemu Windows
    • Klient Windowsa
    • Serwer Windows
  • Lista kolekcji zapytań SCCM
Czytanie: Podgląd techniczny menedżera konfiguracji 2006
Zmiana rozmiaru czcionkiAaa
EnterineEnterine
Zmiana rozmiaru czcionkiAaa
  • DOM
  • To pro
  • Tech
  • Microsoft
  • OKNA
  • Lista kolekcji zapytań SCCM
Szukaj
  • DOM
  • To pro
  • Tech
  • Microsoft
    • Lazur
    • Menedżer konfiguracji/SCCM
    • DPM
    • Orkiestrator
    • Hyper-V.
    • Niejawny tester Microsoft Edge
    • MSI
    • Biuro 365
    • Nieznajomy biura
    • Power bi
    • Skype'a
    • Serwer SQL
    • Zespoły
  • OKNA
    • Centrum administracyjne systemu Windows
    • Klient Windowsa
    • Serwer Windows
  • Lista kolekcji zapytań SCCM
Configmgr

Podgląd techniczny menedżera konfiguracji 2006

Opublikowany: Luty 18, 2024
14 Min. odczyt
UDZIAŁ

Podgląd techniczny menedżera konfiguracji 2006.

Zawartość
Use the Company Portal app on co-managed devicesPrerequisites for Company Portal previewImprovements to available apps via CMGIntranet clients can use a CMG software update pointImprovements to task sequences via CMGKnown issue with OS deployment via CMGManagement insights to optimize for remote workersImprovements to VPN boundary typeTenant Attach: Improvements to Configuration Manager actions in Microsoft Endpoint Manager admin centerCMG support for endpoint protection policiesImport previously created Azure AD application during tenant attach onboardingImprovements to client upgrade on a metered connectionImprovements to managing device restartsImproved support for Windows Virtual DesktopDirect links to Configuration Manager Community hub itemsGeneral known issuesAzure AD authentication doesn’t work

Use the Company Portal app on co-managed devices

The Company Portal is now the cross-platform app portal experience for Microsoft Endpoint Manager. You can now use a preview version of the Company Portal on co-managed devices. By configuring co-managed devices to also use the Company Portal, you can provide a consistent user experience on all devices.

This preview version of the Company Portal supports the following actions:

  • Launch the Company Portal app on co-managed devices and sign in with Azure Active Directory (Usługa Azure AD) single sign-on (SSO).
  • View available and installed Configuration Manager apps in the Company Portal alongside Intune apps.
  • Install available Configuration Manager apps from the Company Portal and receive installation status information.
Company Portal with app from Configuration Manager

The behavior of the Company Portal depends upon your co-management workload configuration:

WorkloadUstawienieBehavior
Client appsConfiguration ManagerYou can see only Configuration Manager client apps
Client appsPilot Intune Lub IntuwaYou can see both Configuration Manager and Intune client apps
Office Click-to-run appsConfiguration ManagerYou can see only Configuration Manager Office click-to-run apps
Office Click-to-run appsPilot Intune Lub IntuwaYou can see only Intune Office click-to-run apps

Prerequisites for Company Portal preview

  • Contact the Company Portal preview team to get started: cppreview@microsoft.com
  • Okna 10, wersja 1803 or later:
    • Enrolled to co-management
    • Access to internet endpoints for Intune
  • The user accounts that sign in to these devices require the following configurations:
    • An Azure AD identity
    • Assigned an Intune license

Improvements to available apps via CMG

An internet-based, domain-joined device that isn’t joined to Azure Active Directory (Usługa Azure AD) and communicates via a cloud management gateway (CMG) can now get apps deployed as available. The Active Directory domain user of the device needs a matching Azure AD identity. When the user starts Software Center, Windows prompts them to enter their Azure AD credentials. They can then see any available apps.

Configure the following prerequisites to enable this functionality:

  • Okna 10 device
    • Joined to your on-premises Active Directory domain
    • Communicate via CMG
  • The site has discovered the user by both Active Directory and Azure AD user discovery

Intranet clients can use a CMG software update point

Intranet clients can now access a CMG software update point when it’s assigned to the boundary group. Admins can allow intranet devices to scan against a CMG software update point in the following scenarios:

  • When an internet machine connects to the VPN, it will continue scanning against the CMG software update point over the internet.
  • If the only software update point for the boundary group is the CMG software update point, then all intranet and internet devices will scan against it.

Improvements to task sequences via CMG

This release includes the following improvements to deploy task sequences to devices that communicate via a cloud management gateway (CMG):

  • Support for OS deployment: With a task sequence that uses a boot image to deploy an OS, you can deploy it to a device that communicates via CMG. The user needs to start the task sequence from Software Center.
  • This release fixes the two known issues from Configuration Manager current branch version 2002. You can now run a task sequence on a device that communicates via CMG in the following circumstances:
    • A workgroup device that you register with a bulk registration token
    • You configure the site for Enhanced HTTP and the management point is HTTP

Known issue with OS deployment via CMG

If there’s an Install Application step in an OS deployment task sequence to a client via CMG, it fails to download the app policy. To work around this issue, disable this step in the task sequence. Deploy the app separately from the task sequence.

Management insights to optimize for remote workers

This release adds a new group of management insights, Optimize for remote workers. These insights help you create better experiences for remote workers and reduce load on your infrastructure. The insights in this release primarily focus on VPN:

  • Define VPN boundary groups: Create a VPN boundary and associate it to a boundary group. Associate VPN-specific site systems to the group, and configure the settings for your environment. This insight checks for at least one boundary group with at least one VPN boundary in it. From the properties of this insight, select Review Actions to go to the Boundary Groups node.
  • Configure VPN connected clients to prefer cloud based content sources: To reduce traffic on the VPN, enable the boundary group option to Prefer cloud based sources over on-premises sources. This option allows clients to download content from the internet instead of distribution points across the VPN.
  • Disable peer to peer content sharing for VPN connected clients: To prevent unnecessary peer-to-peer traffic that likely doesn’t benefit the remote clients, disable the boundary group option to Allow peer downloads in this boundary group.

Improvements to VPN boundary type

You can now create more than one VPN boundary, and can detect the connection by the VPN name or description. When you open the Create Boundary page, and select the VPN typ, choose one of the following options:

  • Auto detect VPN: This option is the same behavior as before. The boundary value in the console list will be AUT:1. It should detect any VPN solution that uses the point-to-point tunneling protocol (PPTP). If it doesn’t detect your VPN, use one of the other options.
  • Connection name: Specify the name of the VPN connection on the device. It’s the name of the network adapter in Windows for the VPN connection. Configuration Manager matches the first 251 characters of the string, but doesn’t support wildcard characters or partial strings. The boundary value in the console list will be NAM:<name>, where <name> is the connection name that you specify. Na przykład, you run the ipconfig command on the device, and one of the sections starts with: PPP adapter ContosoVPN:. Use the string ContosoVPN as the Connection name. It displays in the list as NAM:ContosoVPN.
  • Connection description: Specify the description of the VPN connection. Configuration Manager matches the first 251 characters of the string, but doesn’t support wildcard characters or partial strings. The boundary value in the console list will be DES:<description>, where <description> is the connection description that you specify. Na przykład, you run the ipconfig /all command on the device, and one of the connections includes the following line: Description . . . . . . . . . . . : ContosoMainVPN. Use the string ContosoMainVPN as the Connection description. It displays in the list as DES:ContosoMainVPN.

In every case, the device needs to be connected to the VPN for Configuration Manager to associate the client in that boundary.

Tenant Attach: Improvements to Configuration Manager actions in Microsoft Endpoint Manager admin center

This release introduces some improvements to the administration of Configuration Manager devices in Microsoft Endpoint Manager admin center. Improvements include:

  • Configuration errors now include links to documentation to help you troubleshoot.
  • User available applications now appear in the Applications node for a ConfigMgr device.
    • The application list includes applications deployed to a user currently logged on to the device.
    • Multi-user session scenarios aren’t supported.
    • Azure AD joined devices aren’t currently supported, only AD joined devices.

CMG support for endpoint protection policies

While the cloud management gateway (CMG) has supported endpoint protection policies, devices required access to on-premises domain controllers. Począwszy od tej wersji, clients that communicate via a CMG can immediately apply endpoint protection policies without an active connection to Active Directory.

Import previously created Azure AD application during tenant attach onboarding

During a new onboarding, an administrator can specify a previously created application during onboarding to tenant attach. From the Tenant onboarding page in the Co-management Configuration Wizard, select Optionally import a separate web app to synchronize Configuration Manager client data to Microsoft Endpoint Manager admin center. This option will prompt you to specify the following information for your Azure AD app:

  • Azure AD tenant name
  • Azure AD tenant ID
  • Application name
  • Client ID
  • Secret key
  • Secret key expiry
  • App ID URI

Improvements to client upgrade on a metered connection

Starting in Configuration Manager technical preview version 2005, you could install and upgrade the client when you allowed client communication on a metered connection. You can now also configure the client setting Komunikacja z klientem w ramach taryfowych połączeń internetowych to Limit. This option reduces the client communication on a metered network, but now still allows the client to stay current.

For more information, see the following articles:

  • Technical preview 2005: Zainstaluj i uaktualnij klienta w ramach połączenia taryfowego
  • About client settings: Komunikacja z klientem w ramach taryfowych połączeń internetowych

Improvements to managing device restarts

Configuration Manager provides many options to manage device restart notifications. Na podstawie opinii użytkownika z usługi UserVoice, you can now configure client settings to prevent devices from automatically restarting when a deployment requires it. Domyślnie, Configuration Manager can still force devices to restart.

Ważny:This new client setting applies to all application, software update, and package deployments to the device. Until a user manually restarts the device:

  • Software updates and app revisions may not be fully installed
  • Additional software installs may not happen

Improved support for Windows Virtual Desktop

The Okna 10 Enterprise multi-session platform is available in the list of supported OS versions on objects with requirement rules or applicability lists.

NOTATKA: If you previously selected the top-level Okna 10 platform, this action automatically selected all child platforms. This new platform isn’t automatically selected. If you want to add Okna 10 Enterprise multi-session, manually select it in the list.

Direct links to Configuration Manager Community hub items

You can now easily navigate to and reference items in the Configuration Manager console Community hub node with a direct link. The intention for this feature is for easier collaboration and being able to share links to Community hub items with your colleagues. Obecnie, you’ll see these links shared by the Configuration Manager team and in the documentation.

Na przykład, use this link to share the Configure Edge Auto Update script (https://communityhub.microsoft.com/item/7200). If you have the technical preview branch version 2006 console installed, follow that link, and then select Launch the Community hub. The console opens directly to the script in the Community hub.

NOTATKA:These deep links are currently only for items in the Community hub node of the console.

General known issues

Azure AD authentication doesn’t work

Configuration Manager’s use of the Azure Active Directory (Usługa Azure AD) security token service doesn’t work. The CCM_STS.log on the management point contains an entry similar to the following error: ProcessRequest - Exception: System.IO.FileLoadException: Could not load file or assembly 'System.IdentityModel.Tokens.JWT. It also includes the HRESULT 0x80131040.

Another symptom is issues with a cloud management gateway (CMG). If you run the CMG connection analyzer, it fails testing the CMG channel for management point with the following error: Failed to get ConfigMgr token with Azure AD token. Status code is '500' and status description is 'CMGConnector_InternalServerError'.

This issue is because of a version discrepancy with a supporting library.

To work around the issue, kopia System.IdentityModel.Tokens.JWT.dll from the \bin\X64 folder of the installation directory on the site server to the SMS_CCM\CCM_STS\bin folder on the management point.

OZNACZONE:Aktywny katalogAzure Active DirectoryProchowiecMacOSMECMMEMCMMicrosoft AzureMenedżer konfiguracji punktów końcowych firmy MicrosoftMicrosoft Office 365Niejawny tester pakietu Microsoft OfficeBiuro ProPlusMenedżer konfiguracji programu System CenterOknaOkna 10
Poprzedni artykuł Nieznajomy biura 2006 dla Windowsa
Następny artykuł PowerToys v0.18
Zostaw komentarz Zostaw komentarz

Zostaw odpowiedź Anuluj odpowiedź

Twój adres e-mail nie zostanie opublikowany. Wymagane pola są zaznaczone *

Ta strona korzysta z Akismet w celu ograniczenia spamu. Dowiedz się, jak przetwarzane są dane dotyczące Twoich komentarzy.

Tłumaczenie

English中文(简体)DanskNederlandsFrançaisDeutschItaliano한국어PolskiPortuguêsRomânăEspañolУкраїнська
przez Transposh - translation plugin for wordpress

Popularne posty

Wymagania systemowe dla serwera Windows 2016
Serwer Windows
Lista kolekcji zapytań programu Menedżer konfiguracji
Lista kolekcji zapytań programu Menedżer konfiguracji
Configmgr
Nawigacja strukturalna/zarządzana włączona na nowoczesnych stronach w klasycznych witrynach zespołu
Tech
SCCM Nie udało się uzyskać lokalizacji DP w oczekiwanej wersji z MP
Configmgr

Ostatnie posty

Instalowanie i konfigurowanie Fail2ban dla ochrony SSH na Ubuntu 24.04
Linuksa
Włączanie i konfiguracja FirewallD na AlmaLinux
Linuksa
Tworzenie użytkownika i konfiguracja klucza SSH w AlmaLinux
Linuksa
Jak zresetować hasło w AlmaLinux
Linuksa

© 2023 Enterine

Przejdź do wersji mobilnej
Witamy z powrotem!

Zaloguj się na swoje konto

Nazwa użytkownika lub adres e-mail
Hasło

Zgubiłeś hasło?