CCIT Imaging and PC management System Center Configuration Manager: 2012 Changes and Features Sam Beckler September 26th 2012
Itinerary Migration New features/changes in 2012 Console Changes Imaging Changes
Migration Timeline 9/26/12 Access to imaging 10/8/12 Migrate test containers 10/15/12-10-26/12 Change PXE imaging server Migrate colleges/departments 10/29/12 Use 2007 to push 2012 client to remaining 2007 clients 11/9/12 Remove client connectivity to 2007 environment
Group Policy SCCM2012_Managed_Config SCCM2012_Client_Push SCCM2012_WSUS SCCM_Remote_Assistance SCCM_Firewall_RDP_MSRA SCCM_Firewall_SMB SCCM_Firewall_Wireless_RDP_MSRA SCCM_Firewall_Wireless_SMB
SCCM2012_Managed_Config Provides Automatic certificate enrollment for authentication and encryption Provides code signing certificates for WSUS 3rd Party Updates Basic Firewall settings Allow DHCP server and SCCM Site server to ping client Provide Application Catalog Shortcut Application Catalog fix for if IE is not default browser
SCCM2012_client_push Adds site server (sccm2012.campus.cu.clemson.edu) computer account as local administrator of desktop Adds firewall exceptions to allow only it to connection and distribute the configmgr client
Sccm2012_wsus Provide update server information for automatic configmgr client deployment Also provides code signing certificates for 3rd party updates This GPO will be used as the primary method to migrate computer from 2007 to 2012.
Sccm_Remote_Assistance Enables remote assistance Adds group sccm_admins to remote assistance helpers group
SCCM_Firewall_RDP_MSRA Creates firewall exceptions for remote desktop and remote assistance Local subnet, 130.127.0.0/255.255.0.0, 172.23.0.0/255.255.0.0, 2620:103:a000::/44 Does not include wireless IP ranges
SCCM_Firewall_SMB Creates firewall exceptions for File and Printer sharing Local subnet, 130.127.0.0/255.255.0.0, 172.23.0.0/255.255.0.0, 2620:103:a000::/44 Does not include wireless IP ranges
SCCM_Firewall_Wireless_RDP_MSRA Creates firewall exceptions for remote desktop and remote assistance Allows Wireless IP Ranges
SCCM_Firewall_Wireless_SMB Creates firewall exceptions for File and Printer sharing Allows Wireless IP Ranges
New Features in 2012
User Based Management Currently we deploy software to computers with limited user based delivery SCCM2012 default needs to be user based delivery for a more consistent experience Can still do system based delivery if product requires or delivery doesn’t fit into the user based approval method Benefits User can just go get the software eliminating phone calls, emails, and tickets. If you are not using SCCM Software distribution it also eliminates scheduled visits, bringing in computer, and associated user downtime.
Software Distribution Application Catalog website will display software for users to install (User targeted) Software in the list can be restricted by AD, Central, or BB group Software can be configured to require approval before installing Software Center will display computer targeted software and currently installed software from the Application Catalog provides Software Center provides uninstall ability User does NOT need to have admin rights
Software Distribution New SW_ADV collection structure User Collections Software Distribution Program Program SW_ADV_USER_MAN Shows software in Application Catalog Program SW_ADV_USER_MAN_Approval Requires approval for the user to install Computer Collections Program SW_ADV_MAN Program SW_ADV_AUTO Program SW_ADV_LAB Program SW_ADV_USER Program SW_ADV_Administrative
Power Management Supports configuring power profiles similar to GPO Benefit is you can add two profiles one for peak times and one for off peak times Can configure auto wake time (prefer 5am) User can exempt his/her system from the policy
Software Updates Now delivered through Software Center Will be mandatory install after 5PM Thursday following patch Tuesday Will prompt user to restart Software Center will suspend all activity if the computer is in Presentation mode.
Workgroup Computers Workgroup computers are now supported although functionality is limited No application catalog Not managing software updates No user based software distribution Can use computer based software distribution Communicates over HTTP port 80 Private traffic is still encrypted just at a lower level No internet based management requires VPN to use off campus Stand alone installer Installer can be used on domain joined machines functionality will automatically elevate
Console Changes
Console Changes No longer MMC based System Center has their own console technology that is XML driven Looks very similar to Outlook (even has the ribbons) Provides more information at a glance and less clutter Users and Computers now live in separate spaces No more sub collections structure is now folder based containing collections Collections can still be linked to software using collection linking instead Ability to exclude a collection from another
Console Demo Collection navigation Folder structure Global read permissions not read resource Image collections Advertisement Collections Power Management
Imaging Changes
Registration Screen Minor UI Changes Software tab will change to support new application model Demo
Task Sequences Most Features the same as V3 task sequences Now supports USMT from PE Boot
More Information http://www.clemson.edu/tsp/ipcm http://technet.microsoft.com/en-us/virtuallabs/bb467605.aspx
Questions Q&A