ConfigMgr 2012 Prereq Checker warning: Verify site server permissions to publish to Active Directory

February 8, 2012 Leave a comment

Scenario

During installation of Configuration Manager 2012 RC2 the prerequisite checker lists a warning for the prerequisite: Verify site server permissions to publish to Active Directory although the required permissions are in place.

As the environment might expand and more site servers could be implemented it was opted to grant the permissions using a domain local security group which has the site server computer account added as a member.

Troubleshooting

First check was to verify if the required permissions on the System Management container are  implemented for the group. Additionally it was confirmed the site server computer object was added as a member. When running the prerequisite checker it still shows the warning even though permissions are in place.

In a second scenario permissions were implemented on the System Management container using the computer object instead of using groups. When re-running the prerequisite checker it did no longer show the warning and passed the check.

Resolution

According to feedback received this is behaviour as expected.

This was logged earlier as a bug for the RC1 release of Configuration Manager 2012. The bug report mentioned this would be fixed as of build 7688. Apparently at that point the fix was to reword the explanation offered by the prerequisite checker as opposed to implementing a fix that would have to create a dummy object in AD to test actual permissions.

Bottom line: the warning message can safely be ignored as long as the permissions for the group containing the site server(s) are correctly implemented.

System Center 2012 Major Announcement

January 17, 2012 Leave a comment

Today during a Private Cloud webcast Microsoft has announced their new strategy on System Center. No longer are the System Center products considered as separate entities: System Center 2012 is now a single product. It is a fullblown suite which includes a complete set of System Center products.

An overview of what the suite will include:

  • Configuration Manager
  • Service Manager
  • Virtual Machine Manager
  • Operations Manager
  • Data Protection Manager
  • Orchestrator
  • App Controller
  • Endpoint Protection

This does not mean all of the above will have to be installed in one shot. Customers will still have the ability to implement and integrate solutions one by one.

The new System Center 2012 product comes in 2 editions:

  • The Datacenter edition is licensed per two physical processors and provides use rights for management of an unlimited number of VMs per license.
  • The Standard edition is also licensed per two physical processors, and each license gives you management rights of two virtualized servers.

For details on System Center 2012 licensing have a look here.

Also check out the Private Cloud Assessment Tool.

Evaluation software is available for download here.

Now I am off to the  (virtual) lab for some quality time!

Categories: System Center Tags: , ,

2012

January 17, 2012 Leave a comment

Finally found some time to write up my first post for 2012, so -with some delay- I would like to start by wishing all of you a Happy New Year! I hope 2012 will bring you a lot of professional and personal challenges and successes!  For a System Center enthousiast like myself I am convinced this year will have a lot to offer.

One habit at the beginning of a new year is to come up with good intentions. These are the professional ones which I wrote down for myself, in random order:

Deliver System Center Projects

At the risk of stating the obvious: also this year I want to help customers by designing, implementing and optimizing System Center based solutions. System Center is what I do … (at least) eight hours per day … five days per week and occassionally over the weekend.

Attend MMS  

Probably one of the things I am mostly looking forward to this year is attending the Microsoft Management Summit. After attending TechEd Europe for the past 10+ years, this is the first time I will be attending MMS. I heard a lot of great stories about the event itself and, with the new wave of System Center products about to be released,  I believe this year will be even better.  If you are also attending and would like to meet up in Vegas, please make sure to leave a message.

CMCep Participation

I have been participating in the CMCep program since it kicked off. Not only has it been a very interesting experience in learning ConfigMgr 2012 from its first existence onwards, also the social aspect of it has been really great. The wrap-up of the program is planned for February, so the goal is to participate in the remaining sessions and complete the entire track.

Community Contributions

The System Center community is very much alive and a fun environment to spend time in! My goal is to further actively participate  and contribute to this community. Time will tell how this works out exactly in 2012 … But some ideas are already in the pipeline.

Blog

Not always the easiest of the goals to meet, but I do intend to put some extra effort into my blog. I will be posting more about day-to-day questions and problems I run into at customer sites and how to tackle them. Probably I will  not always opt for the best or most efficient solution – so I am open for feedback and comments on whatever I may post.

See you around in 2012!

Categories: Uncategorized

Techdays Belgium 2012

December 19, 2011 Leave a comment

TechDays 2012 EB BannerlThe next Belgian Techdays are scheduled for February 2012. For the past years the place to be was Antwerp, but for this edition  the event is moving to the south of Brussels  and will take place at Kinepolis Imagibraine in Eigenbrakel.

A quick glance at the session scheduler shows the following System Center related sessions:

  • Monitoring and Operating a Private Cloud with System Center 2012
    Level 300 – Speaker: Adam Hall
  • Configuring and Deploying a Private Cloud with System Center 2012
    Level 300 – Speaker: Adam Hall
  • System Center Virtual Machine Manager 2012, Fabric Management, creation and consumption of the cloud
    Level 300 – Speaker: Vijay Tewari
  • Settings management in ConfigMgr 2012, not your plain old DCM
    Level 300 – Speaker: Kim Oppalfens
  • Deployment Day Session 4: Deployment using SCCM
    Level 300 – Speaker: Rhonda Layfield
  • Deployment Day Session 5: Troubleshooting your SCCM deployments
    Level 300 – Speaker: Rhonda Layfield

Registration and full details at the Techdays 2012 site.

Note: tomorrow is the last day to register and benefit from the early bird discount!

Categories: Events Tags:

ConfigMgr 2012 CEP – PCM & P2V Toolkit Session Key TakeAways

December 15, 2011 Leave a comment

After being absent for a few of the previous CEP sessions I was happy to be able to attend the PCM and P2V Toolkit session yesterday. Below are some key takeaways from this session. This was the last session for this year, next one is scheduled for January 11th 2012.

Package Conversion Manager (PCM)

PCM is a feature pack for Configuration Manager 2012 which will allow you to prepare and move your packages towards the new app model.

A best practice approach to convert packages would be:

  • Migrate Objects
  • Create apps in a lab environment
  • Test apps in a lab environment
  • Export and import

The package migration  options from 2007 to 2012 are:

  • Do nothing and leave the package and program
  • Convert Manually
  • Convert using PCM

Selecting conversion candidates:

  • Good : App-v, MSI and Executable files (user facing applications)
  • Bad: System maintenance tools (defrag, etc …) and end of life applications

Understanding  PCM manual vs automatic conversion rules:

  • Automatic
    • Package contains only 1 MSI
    • No unconverted dependencies exist
    • Content is accessible
  • Manual
    • Must have content
    • Is a software distribution package
    • Contains at least one program

Following up:

  • Using the conversion dashboard
  • Advanced troubleshooting: using the pcmtrace log in the %temp% folder

PCM is scheduled to be released at the same time as Configuration Manager 2012.

Configuration Manager P2V Migration Toolkit

A utility to help migration to Configuration Manager 2012 in specific scenarios, for example  a remote site server migration where the goal is to re-use existing server hardware.

How can the P2V toolkit help:

  • Eliminates the need of parallel physical servers at remote sites
    • Repurpose existing site server into a virtual instance
    • Hosting ConfigMgr 2007 AND ConfigMgr 2012 on the same physical machine using virtualization
  • Simplifies and automates creation of a virtualization task sequence
    • Simple and intuitive interface to create and deploy the task sequence
    • All virtualization tasks sequence steps are built-in
    • Limited input needed by remote site administrators

Toolkit options:

  • Task Sequence with stand alone media (fully automates the end-to-end process)
  • Bootable media only

Offcourse the hardware should meet the necessary prerequisites for virtualization and Hyper-V.

The P2V toolkit will ship at the same time of Configuration Manager 2012 RTM as a separate tool.

The release candicate is already available via Connect.

ConfigMgr 2007 update lists not replicating to child sites

October 7, 2011 Leave a comment

Recently I have ran into an issue at a customer site where software update lists did not properly replicate down to child primary sites. Some of the latest update lists were either incomplete or not visible at all. As a result the customer could not properly advertise the latest software updates.

Initial investigation of the problem shows that the objmgr.box\INCOMING\ and objmgr.box\INCOMING\Retry folders on the child sites contained a lot of unprocessed CID and SDM files. Looking further into the objreplmgr.log errors like to one below are logged:

Processing replication file C:\Program Files (x86)\Microsoft Configuration Manager\inboxes\objmgr.box\INCOMING\Retry\S00_73333.SDM in retry.
Successfully processed Object ScopeId_43C9B1DB-9FC7-4363-8027-36D0C5C24148/AuthList_14C762F6-811D-473F-941F-58B126C93CEF.3
SDM Package ScopeId_43C9B1DB-9FC7-4363-8027-36D0C5C24148/AuthList_14C762F6-811D-473F-941F-58B126C93CEF.3 does not exist in the DB, will insert it with the IsDeleted Flag Set.
SQL MESSAGE: sp_SetupSDMPackage – SDMPackage refers another SDMPackage that is not available yet
sp_SetupSDMPackage returns an error 2
Referenced SDMPackages are not available yet: http://schemas.microsoft.com/systemsmanagementserver/Site_43C9B1DB-9FC7-4363-8027-36D0C5C24148/SUM_cee535ab-0ae5-44e7-8fdf-0f698b27e6f9/1(0);
Failed to Delete Object ScopeId_43C9B1DB-9FC7-4363-8027-36D0C5C24148/AuthList_14C762F6-811D-473F-941F-58B126C93CEF.3. Will add the Replication File C:\Program Files (x86)\Microsoft Configuration Manager\inboxes\objmgr.box\INCOMING\Retry\S00_73333.SDM to the Replication File Retry Queue.

Similar errors exists when the site is processing .CID files.

Interdependencies exists between the different items used for software updates. If the referenced objects are not available the new file will not be correctly processed. It seems that for this particular child site a hickup occured in the replication and the information on the child site is incomplete.

To resolve the issue I ran through the following steps:

1. Stop the SMSEXEC and SMS COMPONENT MANAGER services. This will bring all activity on the site to a standstill.

2. Rename the INCOMING folder to INCOMING_old and recreate an new empty folder structure (so INCOMING and all retry/bad subfolders).
This way we can monitor which files are replicating down and if they are properly being processed, and also see what is being moved into the retry and bad folders.

3. Run the following query on the child site database: Delete from CI_ConfigurationItems Where CIType_ID in (1, 6, 8);
Note that the ID’s may be different for each site. Run the query Select * from CI_Types to get the proper list.
We need to delete the following types: SoftwareUpdate, SoftwareUpdateBundle and AuthorizationList

4. Then run this query: Update CI_SDMPackages set IsDeleted = 1 where SourceSite = ‘XXX’;
Make sure to replace the XXX with the site code of the central site in the hierarchy.

5. And execute the following: Exec sp_DeleteOldSDMPackageData 0;

6. As a final step force a full replication by dropping a XXX.SHA file in the objmgr.box folder on the central site
Here XXX is to be replaced with the site code of the child site.

7. Restart the services stopped in the first step to bring the site back in operational mode.

Shortly after these steps you should see files appearing in the objmgr.box\INCOMING\ folder on the child site again. You can also see if they are being processed in the objreplmgr.log file. Do not be alarmed if initially some files are put in the retry folder again. They will eventually be processed when all dependencies are in place. A full replication can be time consuming: in my case it took over 12 hours for the procedure to complete. Eventually the end result was that the Update Lists showed up completely again.

Note: the above procedure includes making direct changes to the backend database. If you have a support contract I would highly recommend to involve a Microsoft Support representative to ensure you infrastructure remains supported.

ConfigMgr 2012 CEP – SDK Session Key Takeaways

August 15, 2011 Leave a comment

Some key takeaways from the CMCep session held on the 10th of August. Topic for this session was the ConfigMgr 2012 SDK, presented by Heena Macwan and Martin Dey.

 

Planning

 

  • After MMS: SDK Beta program started. On invite only.
  • ConfigMgr 2012 Beta 2 RTM time: SDK Beta available on Connect). Initial draft SDK, including:
    • Coverage for the new AppModel classes and members
    • Draft porting guide
  • ConfigMgr 2012 RTM time: SDK Update, including:
    • Details of all modified classes and members to help port existing solutions
  • ConfigMgr 2012 RTM + 6 Months: SDK RTM
    • Details on all new members and classes
    • Samples and how-to’s

 

SDK Extension Areas

 

  • Admin console
    • Add right-click options, forms, wizards, nodes  and views
    • Insert tabs into existing forms
  • SMS Provider
    • Enabling automation of any UI activity
    • Actions achieved through WMI classes, properties and methods
  • MP interface
    • Allows unsupported clients to be managed through proxy (MP Proxy)
    • Provide extra support for windows clients
  • Client interfaces
    • Exposes interfaces to control panel applet
    • Ability to enact custom policies at the client
    • Note: client inventory customization no longer required

 

Porting from 2007 to 2012

 

  • Some areas will require changes to port to 2012
  • Guidelines will be made available.

 

New Extensibility Areas in 2012

 

  • Application model
  • Settings Management (formerly DCM)
  • RBAC
  • Data Warehouse
  • Mobile Device Management
  • Alerts and Monitoring
  • OSD
  • Software Update Management
  • Client Health

 

Powershell Support

 

  • Phase 1 available at ConfigMgr 2012 RTM : Drive Namespace context and support for get-item access by Object Type
  • Phase 2 at 2 2012 : cmdlets covering key CM WMI namespace objects

 

Follow

Get every new post delivered to your Inbox.

Join 58 other followers