System Center Mobile Device Manager ForumGet answers and guidance on installing, deploying, and managing System Center Mobile Device Manager© 2009 Microsoft Corporation. All rights reserved.Wed, 25 Nov 2009 09:49:04 Zf72ce482-a577-44f6-8ad2-d7f3a292b08ahttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/17448266-8715-4af6-ab37-0e5e154d1e20http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/17448266-8715-4af6-ab37-0e5e154d1e20BoehmeRhttp://social.technet.microsoft.com/Profile/en-US/?user=BoehmeRHow does MDM Device Inventory work? | Problem: slow device after policy update<p>Hello,<br/><br/>i noticed something problematic in our MDM Installation.<br/><br/><strong>Whats happening:</strong><br/>You startup a PDA, everything is going fine, VPN connects, ActiveSync Synchronizes, all fine.<br/>Now you wait for some time ( maybe 8 hours ) or one just start &quot;MDM Connect Now&quot; -&gt; &quot;Connect Now&quot;.<br/>After this manual or automatic policy update we notice the following behaviour on all our Handheld devices.<br/><br/>If you switch of the display (with a short tip at on/off) wait 5 minutes and switch it on again.<br/>The device starts to hang at the logon screen.<br/>You can see the pin mask, sometimes you can even type numbers but always it takes about 1 - 2 minutes to click &quot;unlock&quot;.<br/>After this you get to &quot;today&quot; the time is outdated (showing the time when you switch off the display) it takes another minute for everything to &quot;settle&quot;.<br/>So after 3 minutes the device is suddenly usable, you can open your calendar, the time is correct and so on.</p> <p><strong>What i found out:</strong><br/>So much for our problem, now to the interesting part.<br/>The following was noted by accident.<br/>If i disable the ability to reach the DeviceMgmt Server (due to a misleading host setting for example, or proxy config, or .. ).<br/>Everything is working really fast and without any problem (except for policy updates, which is quite logical).<br/><br/><strong>So what is my problem?</strong><br/>My Problem is that i don't understand what Management feature is slowing down all our devices.<br/>We even got problems on accepting phone calls as the phone UI takes to long to show up.<br/>I tried to track down this issue using jshell ( provided by the MS support ) and taskmanager, both showed nothing out of the ordinary.<br/><br/>All log files are clean, the only thing i noticed was a conflicting GPO setting ( 2 GPO saying opposite things ) which i corrected.<br/>The problem occours on all Windows Mobile 6.1.x releases on nearly 100 devices distributed around 4 device generations ( HTC Diamond, HTC Diamond II, HTC Diamond HD, HTC Diamond Pro, ..).<br/><br/><br/>--- About MDM Inventory ---<br/><br/>As i checked the entire configuration i haven't found any obvious error so i started looking for things which could cause this slow down.<br/>One thing i am quite unsure about is the influence of the &quot;MDM Inventory&quot; does have on the device.<br/>I looked up the Technet but haven't found an answer on how often (interval) and how much data is collected by the inventory.<br/>There is only a way to disable and enable it globally and see the fetched data.<br/><br/><strong>Is it problematic to disable it globally?<br/>Could it cause this Slow down?<br/>How often is the inventory renewed?<br/></strong><br/>I would be really glad if someone even could me with just one of my above asked questions :-)<br/>As i am quite familiar with MDM and all topics related to it you can give me any technical details or food for thoughts.<br/><br/><br/>with best regards,<br/><br/>Robert</p>Fri, 18 Sep 2009 14:04:19 Z2009-11-25T09:49:04Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/5af251ec-90d3-476b-b3bd-13463f211f83http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/5af251ec-90d3-476b-b3bd-13463f211f83southernbearhttp://social.technet.microsoft.com/Profile/en-US/?user=southernbearcan SCDM support the mobile devices which are using Windows XP or Windows 7?Would like to know if SCDM can only manage Windows mobile 6.1 or it can also manage the windows XP and Window 7 devices?&nbsp; is there any specific hardware requirement on the managed devices?Thu, 15 Oct 2009 16:02:21 Z2009-11-25T09:16:08Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/05d4096a-83eb-4932-bb10-41123587ecb0http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/05d4096a-83eb-4932-bb10-41123587ecb0CraigMucklestonhttp://social.technet.microsoft.com/Profile/en-US/?user=CraigMucklestonDisplaying Device KeyboardI am developing a mobile app on a Windows Mobile 6.1 device. I have a textbox. I want the user to be able to enter text. However, I can't display the keyboard. How can I?Tue, 24 Nov 2009 14:30:26 Z2009-11-25T02:18:47Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/36e5d42c-fa3e-4cd7-a504-ceeb8d819ea2http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/36e5d42c-fa3e-4cd7-a504-ceeb8d819ea2WindCloudhttp://social.technet.microsoft.com/Profile/en-US/?user=WindCloudGateway Vs DeviceI have 2 Gateway servers, 1 DM server and 1 Enrollment server in my environment.<br/><br/>My question is, will the enrolled device stored any one of the Gateway server IP as default for communication after the enrollment?<br/><br/>If yes, any way to find out which Gateway server IP address has been stored by the device?<br/><br/>Thank.<br/>KCWed, 18 Nov 2009 15:37:22 Z2009-11-25T02:16:43Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/b8a62e15-4a86-464f-be55-421de199dbf6http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/b8a62e15-4a86-464f-be55-421de199dbf6ChrisEdg87http://social.technet.microsoft.com/Profile/en-US/?user=ChrisEdg87Adding a Gateway ServerHi,<br/><br/>Currently we have 1 Gatway Server and 1 Management/Enrollment Server that we were using for testing. Now we would like to go Live with the system how easy would it be to add an additional Gatway server for redundacny purposes?<br/><br/>Do we simply need to add 2 A Name dns records to point to the 2 ip address and then send the updated Gateway address over Group Policy? Or do we need to configure things like Microsoft NLB on the gatway servers?<br/><br/>Thanks,<br/>ChrisMon, 23 Nov 2009 11:41:41 Z2009-11-25T02:12:07Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/3c09b50f-ae53-4903-a73f-ef7905999a3ahttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/3c09b50f-ae53-4903-a73f-ef7905999a3aCraigMucklestonhttp://social.technet.microsoft.com/Profile/en-US/?user=CraigMucklestonUnable to keep Focus on TextBoxI have an app I'm developing for WM6.1. I have a Textbox and a ListBox. Everytime set the DataSource of the ListBox, I lose focus of my TextBox and can't get it back. Without the ListBox, it's fine.<br/><br/>What's the deal? Any solutions?Tue, 24 Nov 2009 16:04:20 Z2009-11-25T02:18:21Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/379b5a3b-6aa0-4d9f-87be-70d9d223d93dhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/379b5a3b-6aa0-4d9f-87be-70d9d223d93dTesdallhttp://social.technet.microsoft.com/Profile/en-US/?user=TesdallMicrosoft System Center Mobile Device Manager 2008 vs other software<p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-family:Verdana;color:black;font-size:8pt">We were looking for software to manage our mobile work force and we came across Trust Digital. However, that was before we set our standards to windows mobile 6.1 phones. How does Mobile Device Manager compare to Trust Digitals software? Does anyone know?<br/><br/>Also, what can exchange 2010 do that device manager can or cannot do?</span></p>Tue, 24 Nov 2009 19:59:28 Z2009-11-24T19:59:28Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/18c36947-2862-4895-9972-c82516fd7730http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/18c36947-2862-4895-9972-c82516fd7730Espen BEhttp://social.technet.microsoft.com/Profile/en-US/?user=Espen%20BESCCM v.Next!<span lang=EN-US><span style="font-family:Calibri"> <p class=MsoNormal style="margin:0cm 0cm 10pt"><span lang=EN-US><span style="font-size:small">I have seen from some Blog’s from Tech-Ed Berlin that MDM will merge into SCCM. To my <strong>horror</strong> I also see that the VPN access solution will be removed from this version. Is this correct? </span></span></p> <span lang=EN-US><span style="font-family:Calibri"> <p class=MsoNormal style="margin:0cm 0cm 10pt"> </p> </span><span style="font-size:small"><span style="font-family:Calibri">Espen </span></span></span></span> </span>Fri, 13 Nov 2009 14:43:06 Z2009-11-23T16:50:52Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/5b4024c6-8dbd-4dfc-ad7b-3de6be5a9bcchttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/5b4024c6-8dbd-4dfc-ad7b-3de6be5a9bccWindCloudhttp://social.technet.microsoft.com/Profile/en-US/?user=WindCloudVersion VerificationHow/where to verify for my SCMDM version install?  I like to check if it been patch to SCMDM 2008 SP1 but no clue where to check for it?<br/><br/>I had checked on Add/Remove program, it only show 1.0.4050<br/><br/>Thanks again.<br/><br/>Cheers,<br/>KCFri, 20 Nov 2009 09:31:43 Z2009-11-21T16:32:17Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/1df0b835-23e0-4fc3-9b90-b81536b2ab19http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/1df0b835-23e0-4fc3-9b90-b81536b2ab19Michael Pearnhttp://social.technet.microsoft.com/Profile/en-US/?user=Michael%20PearnIssue with initiating VPN connection across GPRS, wireless 802.1x works fine though<p class=MsoNormal>Hi all,</p> <p class=MsoNormal>I’m having an issue with two recent customers deployments of System Center Mobile Device Manager 2008 SP1 (MDM).</p> <p class=MsoNormal>Basically, from all my test Windows Mobile 6.1+ devices, I can connect to the MDM Gateway server across two different wireless 802.1X connections and get a VPN IP address via a VPN tunnel and the solution works 100%.</p> <p class=MsoNormal>However, I cannot get the Windows Mobile devices to initiate the VPN tunnel using a GPRS connection.  One customer has a Vodafone (UK) connection and we’ve had discussions about using various different APNs without success.  The other customer has an O2 connection (UK) and we’ve only just engaged with them.  Both customers have their own MDM Gateway servers with two different public DNS names.</p> <p class=MsoNormal>Also, another curious issue, is that if you initiate the VPN tunnel across a 802.1X connection, then disable the wireless network – the VPN tunnel then switches to the GPRS connection and continues fine!  Also the MDM port infiltration tests work fine across GPRS as well. So it appears the issue is limited to initiating the VPN tunnel only across one of the IPSEC ports.</p> <p class=MsoNormal>The MDM VPN testing tool logging, just gives me the following error:</p> <p class=MsoNormal> </p> <p class=MsoNormal> <p class=MsoNormal>LOG-N:11-20.11:03:44- IPsecVPNPM: Using default connections.</p> <p class=MsoNormal>LOG-I:11-20.11:03:47- IPsecVPNPM: STATE: [StateDNSResolve].</p> <p class=MsoNormal>LOG-I:11-20.11:03:49- IPsecVPNPM: STATE: [StateTunnelSetup].</p> <p class=MsoNormal>LOG-I:11-20.11:03:49- IKE SA Lifetime: 26280 seconds.</p> <p class=MsoNormal>LOG-I:11-20.11:03:49- IPSec SA Lifetime: 21600 seconds.</p> <p class=MsoNormal>LOG-I:11-20.11:03:49- IPsecVPNPM: commit succeeded.</p> <p class=MsoNormal>LOG-I:11-20.11:03:49- IPsecVPNPM: STATE: [StateWaitForTunnel].</p> <p class=MsoNormal>LOG-E:11-20.11:04:02- IPsecVPNPM: ActiveSync notification.</p> <p class=MsoNormal> </p> <p class=MsoNormal>LOG-I:11-20.11:04:06- BASE CONNECTION DOWN: Marking tunnel local IPs changed, static IP disappeared</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- </p> <p class=MsoNormal>LOG-I:11-20.11:04:19- IKEv2 SA [Initiator] negotiation failed:</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- </p> <p class=MsoNormal>LOG-I:11-20.11:04:19-   Local IKE peer  x.x.x.x:4500 ID (null)</p> <p class=MsoNormal>LOG-I:11-20.11:04:19-   Remote IKE peer x.x.x.x:4500 ID (null)</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- </p> <p class=MsoNormal>LOG-I:11-20.11:04:19-   Message: Invalid argument (65538)</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- IKE SA negotiations: 4 done, 0 successful, 4 failed</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- </p> <p class=MsoNormal>LOG-I:11-20.11:04:19- IPsec SA [Initiator] negotiation failed:</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- </p> <p class=MsoNormal>LOG-I:11-20.11:04:19-   Local IKE peer  x.x.x.x:4500 ID (null)</p> <p class=MsoNormal>LOG-I:11-20.11:04:19-   Remote IKE peer x.x.x.x:4500 ID (null)</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- </p> <p class=MsoNormal>LOG-I:11-20.11:04:19-   Message: Invalid argument (65538)</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- IPsec SA negotiations: 4 done, 0 successful, 4 failed</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- Phase-I negotiation failed</p> <p class=MsoNormal>LOG-I:11-20.11:04:19-   Message: Invalid argument (65538)</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- IPsecVPNPM: Tunnel down: Mobike was not operational</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- IPsecVPNPM: STATE: [StatePurgeRules].</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- IPsecVPNPM: Deleting the Tunnel</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- IPsecVPNPM: commit succeeded.</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- IPsecVPNPM: STATE: [StateDefaultPolicy].</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- IPsecVPNPM: STATE: [StateDefaultRun].</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- IPSEC VPN TUNNEL RETRY DELAY: 119 seconds.</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- IPsecVPNPM: Set the CESetUserNotification</p> <p class=MsoNormal>LOG-I:11-20.11:04:19- IPsecVPNPM: out of UnAttended Mode.</p> <p class=MsoNormal> </p> <p class=MsoNormal>A person in the Netherlands seems like he’s had the exact same issue on the Microsoft TechNet forums, however his resolution in dealing with his Telco appeared to resolve the problem: </p> </p> <p class=MsoNormal><a href="http://social.technet.microsoft.com/Forums/en/SCMDM/thread/b1936e3f-bf4c-45a3-96ba-0343ef6725b2">http://social.technet.microsoft.com/Forums/en/SCMDM/thread/b1936e3f-bf4c-45a3-96ba-0343ef6725b2</a></p> <p class=MsoNormal>We’re currently investigating trialling a dedicated Vodafone tunnel straight through to the router where the MDM gateway server sits, however I don't know if this will solve the issue.</p> <p class=MsoNormal>Has anyone seem this problem before and/or could steer me in the right direction?  I haven’t been able to use a GPRS enabled SIM with a correct APN setting to test this connection once successfully, so I cannot work out whether it’s device, APN, or something wrong with the MDM Gateway server dealing with GPRS connections.</p> <p class=MsoNormal> </p> <span style="font-size:11.0pt;font-family:'Calibri','sans-serif'">Cheers if anyone can help</span> <div><span style="font-family:Calibri, sans-serif;font-size:medium"><span style="font-size:15px"><br/></span></span></div> <div><span style="font-family:Calibri, sans-serif;font-size:medium"><span style="font-size:15px">Michael</span></span></div> <div><span style="font-family:Calibri, sans-serif;font-size:medium"><span style="font-size:15px">mpearn@gmail.com</span></span></div> <div><span style="font-family:Calibri, sans-serif;font-size:medium"><span style="font-size:15px"><br/></span></span></div>Fri, 20 Nov 2009 11:07:19 Z2009-11-20T11:07:20Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/9bec590b-d524-433a-946f-d61e86ff85cfhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/9bec590b-d524-433a-946f-d61e86ff85cfChrisEdg87http://social.technet.microsoft.com/Profile/en-US/?user=ChrisEdg87MDM Stopped WorkingHello,<br/><br/>We have a very strange problem. Up until a couple days ago our MDM setup was working perfectly. Enrollment, Management, Software Distribution were all working as expected. We then needed to reboot our Gateway server and since then none of our Devices have been able to connect! <br/><br/>The VPN doesn't show any problems with no errors on the device or server. The Gateway Server shows an up to date state in the Management Console and our devices are still able to access other network resources such as email through Active Sync. <br/><br/>So the problem seems to be the connection to the management server right? I can browse to <a href="https://dm.&lt;domain&gt;:8443/mdm/tee/handler.ashx">https://dm.&lt;domain&gt;:8443/mdm/tee/handler.ashx</a> from a machine on the network but not from a device. Looking at our internal firewall logs I can see traffic reaching the Management server but its like it doesn't know where to send the reply.<br/><br/>Device logs show the following error - <br/><br/>2009-11-19 08:24:58 omadmclient.exe: Failed sending an HTTP request to the server (0x80072ee2).<br/>2009-11-19 08:24:58 omadmclient.exe: [PID = 0xab054fc2] - Transmitting package data FAILED (hr = 0x80072ee2)<br/>2009-11-19 08:24:58 omadmclient.exe: Data transmission attempt 1/6 failed (0x80072ee2).<br/>2009-11-19 08:24:58 omadmclient.exe: Data transmission failure is retriable.<br/>2009-11-19 08:24:58 omadmclient.exe: Backing off for 30000 milliseconds.<br/>2009-11-19 08:25:28 omadmclient.exe: [PID = 0xab054fc2] + Transmitting package data<br/>2009-11-19 08:25:28 omadmclient.exe: [PID = 0xab054fc2] + Initializing wininet<br/>2009-11-19 08:25:28 omadmclient.exe: [PID = 0xab054fc2] - Initializing wininet<br/>2009-11-19 08:25:28 omadmclient.exe: Additional headers sent to server = &quot;Content-Type: application/vnd.syncml.dm+wbxml<br/><br/>Anyone have any ideas?Thu, 19 Nov 2009 15:09:13 Z2009-11-20T08:54:06Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/69b261f3-a45e-4641-9c71-ef36a4c3d92bhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/69b261f3-a45e-4641-9c71-ef36a4c3d92bWindCloudhttp://social.technet.microsoft.com/Profile/en-US/?user=WindCloudServer Resource Kit ToolsAnyone has successfully use of the tools:<br/><br/>1. Device Enrollment Cleanup Tool<br/>2. Device Records Synchronization Tool<br/>3. Blocked Device Cleanup Tool<br/><br/>I have tried but never success for any one of it.<br/><br/>The device still showing on the DM console, All Managed Device and Blocked Device list.<br/><br/>Anyone can share if you have any info about the tools?<br/><br/>Thanks.<br/>KCWed, 18 Nov 2009 15:49:29 Z2009-11-20T08:27:47Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/1831046b-9b16-4c9c-bafb-0c6952a45386http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/1831046b-9b16-4c9c-bafb-0c6952a45386Arnold Hhttp://social.technet.microsoft.com/Profile/en-US/?user=Arnold%20HGCM service cannot find a valid certificateI get errors:<br/> &quot;5257: Gateway Central Management service cannot find a valid certificate to authenticate with the Gateways. The service can automatically detect a valid installed certificate issued with the Gateway Central Management template. Install a valid certificate and then restart the service.&quot;<br/> and<br/> &quot;5258: Gateway Central Management service did not connect to any Gateway Server. Make sure that all Gateway Servers are running and are reachable from this computer, and that this computer can resolve the DNS names of the Gateway Servers.&quot;<br/> I have seen there few times here on the technet forums, but I can not get my GCM to connect to the GW with those answers.<br/> <br/> This is what I tried:<br/> 1) In the MDM console I see: Service Configuration State: Running and Sync State: Unreachable.<br/> 2) With the MDM ResKit:<br/> &gt; MDMCert.exe /install /mdminstance:iiii /ca:&quot;bbb\CA ccc&quot;<br/> &gt; MDMCert.exe /validate /mdminstance:iiii /ca:&quot;bbb\CA ccc&quot; /endpoint:gcm<br/> The following is a filtered list of Gateway Central Management (GCM) certificates and validity statuses:<br/> &lt;Subject&gt;                  &lt;Issued Date&gt;   &lt;Issued By&gt;      &lt;Expiration Date&gt;   &lt;Valid/Invalid&gt;<br/> CN=aaaaa             13-11-2009        bbbl\CA ccc    13-11-2011 Valid<br/> Log file is created at: C:\Program Files\MDMResourceKit\MDMServerTools\MDMCertificate\MDMCert[2009_11_13][11_05_08].log<br/> So this tells me the certificate is valid and the ACL for the NETWORK SERVICE is correct<br/> 3) Using a browser on the MDM/GCM I can connect to https://fqdn.of.the.gw/Vpn/applyconfig.ashx and is asking me for a client certificate (which of course does not exist im my current-user store)<br/> <br/> So the certificate is correct and the GW is reachable by its fqdn. <br/> Where to go next?<br/> <br/> Thanks in advance.<br/> Arnold<img style="border:medium none;z-index:2147483647" alt="" width=24 height=24>Fri, 13 Nov 2009 10:56:03 Z2009-11-20T08:38:16Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/29c7b591-dc04-4ab9-a092-e7ee1e9e9697http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/29c7b591-dc04-4ab9-a092-e7ee1e9e9697Ras11mhttp://social.technet.microsoft.com/Profile/en-US/?user=Ras11mAntivirus Exclusions on SCMDM ServersHi there Guys,<br/><br/>Is there any document or article on the internet outlining what to exclude when installing 3rd paty antivirus software on SCMDM servers? Including SCMDM gaateway server as well as enrollment and device management server? <br/><br/>Best Regards,<br/><br/>RasWed, 11 Nov 2009 04:49:57 Z2009-11-20T03:03:30Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/7950b1ba-4232-499e-b1e4-bad7193b9c95http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/7950b1ba-4232-499e-b1e4-bad7193b9c95hallal_1981http://social.technet.microsoft.com/Profile/en-US/?user=hallal_1981big problem i cant read any arabic texts on my htc hd2 6.5 windows version is thereany way to install software or update thnxThu, 19 Nov 2009 07:58:11 Z2009-11-19T23:45:04Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/5879f231-0f74-4d7b-b736-c8bbff08551bhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/5879f231-0f74-4d7b-b736-c8bbff08551bJ.C. Hornbeckhttp://social.technet.microsoft.com/Profile/en-US/?user=J.C.%20HornbeckSystem Center Mobile Device Manager : Resolving Software Distribution 8041 warningsHere’s a problem which we’ve seen a couple of times which can be caused by bad packages in software distribution.  This problem can arise when Software Distribution is being used, and you notice that devices don’t seem to be getting packages, nor getting updated in the Software Distribution console.  As well as this, the following message is logged in the MDM event log on the Device Management Server:<br/><br/>Event Type:        Warning<br/>Event Source:    Device Manager<br/>Event ID:              8041<br/>Description:<br/>Software Distribution service received insufficient query results from device {DeviceSID}.<br/>Missing LocUri ./Vendor/MSFT/SwMgmt/Download?list=StructData. <br/><br/>Steps for resolving this issue are at <a href="http://blogs.technet.com/mdm/archive/2009/11/02/software-distribution-8041-warning.aspx">http://blogs.technet.com/mdm/archive/2009/11/02/software-distribution-8041-warning.aspx</a><br/><br/>J.C. Hornbeck | MicrosoftMon, 02 Nov 2009 16:05:12 Z2009-11-19T16:03:47Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/8d11bc73-bcb7-40f5-bd95-de4f9c03a76bhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/8d11bc73-bcb7-40f5-bd95-de4f9c03a76bguillermotaylorhttp://social.technet.microsoft.com/Profile/en-US/?user=guillermotaylorSQL role on Windows Server 2008<span style="font-family:'Calibri','sans-serif';font-size:11pt" lang=EN-US>Hello all. Although I suspect the answer, I want to know if SQL role in SCMDM 2008 SP1 can be configured on Windows Server 2008. Customer says he already has a SQL Server 2005 running on Windows Server 2008 and he would like to use that one.<br/><br/>Thanks,<br/><br/><br/>Guillermo</span>Wed, 18 Nov 2009 11:56:52 Z2009-11-25T02:12:26Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/3499efc9-0d67-4b0d-91c6-758687e3d42ahttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/3499efc9-0d67-4b0d-91c6-758687e3d42aChrisEdg87http://social.technet.microsoft.com/Profile/en-US/?user=ChrisEdg87Enrollment Autodiscovery<p>Hi,<br/>We have MDM up and running almost perfectly. Our only problem is that during the enrollement process the devices never seem to be able to auto discover the enrollement server.<br/>The server is publish using ISA as mobileenroll.&lt;domain.co.uk&gt; and the devices can resolve this ok as it works when we manually input the server name.<br/>I think the problem could be that our domain name and our email address are not the same, but does anyone know of any way around this?<br/>Thanks</p>Mon, 09 Nov 2009 14:51:44 Z2009-11-11T11:57:54Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/7c143c82-7926-4d77-a368-d60eb4f274d3http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/7c143c82-7926-4d77-a368-d60eb4f274d3Ras11mhttp://social.technet.microsoft.com/Profile/en-US/?user=Ras11mSCMDM 2008 SP1 - Device removal procedure?How do i go about to removing a device from the scmdm console? I managed to run removedevice powershell cmdlet it successfully removes the device from the domain and adds it to block list i then run clean up of blocked devices powershell cmdlet but the device still appears in the all devices section. Is there a way of removing them from the console completely? <br/><br/>I read on these forums that we might need to update TEE.db? If so how can that be done ?<br/><br/>Cheers<br/><br/>Ras<br/>Fri, 23 Oct 2009 00:13:27 Z2009-11-11T11:06:41Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/00c18e01-4ab4-4815-befd-c00ba945ec50http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/00c18e01-4ab4-4815-befd-c00ba945ec50maettu99http://social.technet.microsoft.com/Profile/en-US/?user=maettu99Active Directory Objects and Attributes used by SCMDMHello,<br/><br/>Can you guys tell me wich AD object and attributes are used by SCMDM to create an AD account for a mobile device? Are these computer objects in Active Directory?<br/><br/>Thanks and regards<br/><br/>matThu, 05 Nov 2009 06:52:58 Z2009-11-20T06:20:05Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/868d7b26-851f-45c9-9850-b1827b22c007http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/868d7b26-851f-45c9-9850-b1827b22c007Ras11mhttp://social.technet.microsoft.com/Profile/en-US/?user=Ras11mSCMDM Gateway server WAN connectionHi there guys , <br/><br/>I really hope this is something you can help me with. I have got a requirement that the public IP of the SCMDM gateway server will need to sit behind a firewall. <br/><br/>From the reading I have done so far NAT for the public interface is not supported!(well at least you wont get full functionality out of it). I have got a Cisco ASA firewall and have bunch of public ips available. <br/><br/>My SCMDM gateway is sitting in the DMZ nic 1 has a DMZ ip address assigned to it and nic 2 to has a public ip. Is there a way of setting this up so that the public interface sits behind the firewall as well? As at the moment some traffic is bypassing the Firewall and this raises some security concerns. <br/><br/>I would like to find out how everyone else is handling their public ip interfaces on the gateway server.<br/><br/>I intend to configure the server to be accessible from the internet is it sufficient to configure static NAT with 1:1 mapping of official to public IP or PAT. Does SCMDM Gateway support this option?<br/><br/>Cheers<br/><br/>Ras<br/>Wed, 28 Oct 2009 08:56:21 Z2009-11-09T00:20:25Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/3f2d2889-c304-4905-9e36-fd42393fbc20http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/3f2d2889-c304-4905-9e36-fd42393fbc20Yaroslav Turbinhttp://social.technet.microsoft.com/Profile/en-US/?user=Yaroslav%20TurbinError with CA then do pre-deployment stepsHello!<br/>I have problem with deployment Mobile Device Manager.<br/>I have offline root CA based on Windows Server 2003 and clustered subordinate CA based on Windows Server 2008 Enterprise.<br/><br/>When i prepare my infrastructure for MDM and do command adconfig /enabletemplates i see error:<br/><br/><em>[11/04/2009-21:41:20] DEBUG : Invoking RunDll with arguments &quot;C:\MDM\adconfig\CertificateAuthorityPermissions_x64.dll&quot;,InstallCASecurity vcngsubca.vcng.ru vcngsubca01 S-1-5-21-676356331-940865192-3957312832-1127 S-1-5-21-676356331-940865192-3957312832-1128 S-1-5-21-676356331-940865192-3957312832-1122<br/>[11/04/2009-21:41:21] DEBUG : Rundll exited with error code -2147024891<br/>[11/04/2009-21:41:21] ERROR : Failed to add security on the vcngsubca.vcng.ru\\vcngsubca01 certification authority using trustee security identifier [S-1-5-21-676356331-940865192-3957312832-1127], and subject security identifier [S-1-5-21-676356331-940865192-3957312832-1128]. Error: Access is denied.<br/>[11/04/2009-21:41:21] DEBUG : Failed to add security on the vcngsubca.vcng.ru\\vcngsubca01 certification authority using trustee security identifier [S-1-5-21-676356331-940865192-3957312832-1127], and subject security identifier [S-1-5-21-676356331-940865192-3957312832-1128]. Error: System.ComponentModel.Win32Exception: Access is denied<br/>   at Microsoft.MobileDeviceManager.InstanceManager.CertificateAuthoritySecurity.CallExportedNativeMethod(String nativedll, String methodName, String args, Boolean bReturnExitCode)<br/>   at Microsoft.MobileDeviceManager.InstanceManager.CertificateAuthoritySecurity.AddSecurity(String certificationAuthority, IMDMProductInstance mdmInstance).<br/>[11/04/2009-21:41:21] ERROR : Errors occurred while configuring security on vcngsubca.vcng.ru\vcngsubca01 certification authority for MDM instance VCNGMobile.<br/><br/></em>I check this KB: <a href="http://support.microsoft.com/kb/927066/">http://support.microsoft.com/kb/927066/</a> and it not help me.<br/><br/>But then in log i see:<br/><br/><em>[11/04/2009-21:41:21] INFO : Using BindRoot </em><a><em>LDAP://rootDSE</em></a><br/><em>[11/04/2009-21:41:21] DEBUG : Created directory entry for [DN=LDAP://rootDSE].<br/>[11/04/2009-21:41:21] DEBUG : Created directory entry for [DN=LDAP://CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration,DC=vcng,DC=ru].<br/>[11/04/2009-21:41:21] DEBUG : Considering CA VCNGSubCA.vcng.ru\VCNGSubCA01. Check if CommonName is matching vcngsubca01<br/>[11/04/2009-21:41:21] DEBUG : Found CA vcngsubca.vcng.ru\vcngsubca01.<br/>[11/04/2009-21:41:21] DEBUG : Considering CA VCNGSubCA.vcng.ru\VCNGSubCA01.<br/>[11/04/2009-21:41:21] DEBUG : Found CA vcngsubca.vcng.ru\vcngsubca01.<br/>[11/04/2009-21:41:21] DEBUG : The vcngsubca.vcng.ru\vcngsubca01 certification authority has dNSHostName = VCNGSubCA.vcng.ru.<br/>[11/04/2009-21:41:21] DEBUG : Attempting to find the CERTSVC_DCOM_ACCESS group in the vcng.ru domain.<br/>[11/04/2009-21:41:21] INFO : Using BindRoot </em><a><em>LDAP://vcng.ru/rootDSE</em></a><br/><em>[11/04/2009-21:41:21] DEBUG : Created directory entry for [DN=LDAP://vcng.ru/rootDSE].<br/>[11/04/2009-21:41:21] DEBUG : Created directory entry for [DN=LDAP://DC=vcng,DC=ru].<br/>[11/04/2009-21:41:21] DEBUG : Searching for well-known group using search filter [(&amp;(samAccountName=CERTSVC_DCOM_ACCESS)(objectCategory=group))] and search root [LDAP://DC=vcng,DC=ru].<br/>[11/04/2009-21:41:21] INFO : Found no groups using search filter [(&amp;(samAccountName=CERTSVC_DCOM_ACCESS)(objectCategory=group))] and search root [LDAP://DC=vcng,DC=ru].<br/>[11/04/2009-21:41:21] DEBUG : Did not find the CERTSVC_DCOM_ACCESS group in the vcng.ru domain.<br/>[11/04/2009-21:41:21] INFO : The CERTSVC_DCOM_ACCESS group does not exist in the domain for the vcngsubca.vcng.ru\vcngsubca01 certification authority.<br/>[11/04/2009-21:41:21] INFO : </em><strong><em>Result of AD Configuration Operation: Success<br/><br/></em></strong>And i dont undestand: preconfiguration step normal or not.Wed, 04 Nov 2009 15:57:32 Z2009-11-09T00:17:34Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/eb1052ec-b0bb-4beb-98c5-d804f221011bhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/eb1052ec-b0bb-4beb-98c5-d804f221011bTBorelyhttp://social.technet.microsoft.com/Profile/en-US/?user=TBorelyBenq Mobile Registry Access DeniedI currenlty have a Benq e72 mobile phone running windows mobile 6.1 and in order to see who was calling I downloaded a mobile registry editor to modify the CallerID from 8 to 7.<br/><br/>However, I needed to do a master reset on the phone and now when I am trying to redo the edit, I am getting Access DeniedSun, 08 Nov 2009 11:28:10 Z2009-11-09T05:57:14Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/6ca612e4-7f6d-4979-982c-0c38a707884ehttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/6ca612e4-7f6d-4979-982c-0c38a707884eym81http://social.technet.microsoft.com/Profile/en-US/?user=ym81SCMDM activesync policies to block email from sync-ing to deviceHi,<br/>   I used SCMDM user policies to apply to my test user using the WM6.1 professional emulator.  The policies for this user are supposed to:<br/> <br/> 1) Set maximum attachment allowed = 0 (Block all attachments)<br/> <br/> 2) Set maximum size limit for plain text e-mail = Header Only<br/> <br/> 3) Set maximum size limit for HTML text e-mail = Header Only.<br/> <br/>   These policies are effective on the enrolled user as shown by the Windows Mobile Group Policy Results.<br/> <br/>   I proceeded to setup the Activesync account for the user to access the Exchange 2007 server.  I was expecting that the user's calendar data gets downloaded but emails and attachments are not supposed to be downloaded (should just see headers in Outlook Mobile) as they are set by the policies.<br/> <br/>   I realised that when they are first sync, indeed only the headers are downloaded (0/XXk is shown).  But when I access the email, I can still click to download the emails and the entire message.  Are the policies supposed to work like this or did I configure wrongly?  I was expecting no email body and attachments could be downloaded to the device.<br/> <br/>   Thanks.Wed, 04 Nov 2009 07:33:39 Z2009-11-09T05:57:31Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/6b8cb8be-2e05-4c61-b7fc-468852f98df4http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/6b8cb8be-2e05-4c61-b7fc-468852f98df4Jorge Delgado-Lopezhttp://social.technet.microsoft.com/Profile/en-US/?user=Jorge%20Delgado-LopezPolicies for 6.5Hi, <div><br/></div> <div>Are there any differences between 6.1 and 6.5 when it comes to policies? I can't seem to find an updated list, just the classic http://technet.microsoft.com/en-us/library/dd261953.aspx and it says nothing about 6.5 changes, additions or any new ADM file.</div> <div><br/></div> <div>Thanks,</div> <div>- jorge</div>Fri, 06 Nov 2009 15:39:10 Z2009-11-20T03:00:02Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/18250ef9-420c-440b-91ad-cf91176897d1http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/18250ef9-420c-440b-91ad-cf91176897d1J.C. Hornbeckhttp://social.technet.microsoft.com/Profile/en-US/?user=J.C.%20HornbeckAutomatic FixIt: You receive error 401.1 when you browse a Web site that uses Integrated Authentication and is hosted on IIS 5.1 or a later versionI asked the FixIt team for this a while back and they have delivered.  Now if you ever run into the symptoms below the chances are good we can automatically fix it with just a few clicks of the mouse: <p><strong>The Symptoms:</strong> When you use the fully qualified domain name (FQDN) or a custom host header to browse a local Web site that is hosted on a computer that is running Microsoft Internet Information Services (IIS) 5.1 or a later version, you may receive an error message that resembles the following:</p> <p><a href="http://blogs.technet.com/blogfiles/configurationmgr/WindowsLiveWriter/AutomaticFixItYoureceiv.1oralaterversion_D373/image_4.png"><span style="color:#000000"><img style="border-bottom:0px;border-left:0px;margin-left:auto;border-top:0px;margin-right:auto;border-right:0px" title=image src="http://blogs.technet.com/blogfiles/configurationmgr/WindowsLiveWriter/AutomaticFixItYoureceiv.1oralaterversion_D373/image_thumb_1.png" border=0 alt=image width=400 height=47></span></a></p> <p align=center><em>HTTP 401.1 – Unauthorized: Logon Failed</em></p> <p><em><strong>Note</strong> You only receive this error message if you try to browse the Web site directly on the server. If you browse the Web site from a client computer, the Web site works as expected.</em></p> <p><span style="color:#004080"><span style="color:#000000">Additionally, an event message that resembles the following event message is logged in the Security Event log. This event message includes some strange characters in the value for the Logon Process entry:</span> </span></p> <p><span style="color:#004080">Event Type: Failure Audit <br/>Event Source: Security <br/>Event Category: Logon/Logoff <br/>Event ID: 537 <br/>Date: Date <br/>Time: Time <br/>User: NT AUTHORITY\SYSTEM <br/>Computer: Computer_Name <br/>Description: Logon Failure: <br/>Reason: An error occurred during logon <br/>User Name: User_Name <br/>Domain: Domain_Name <br/>Logon Type: 3 <br/>Logon Process: Ðùº <br/>Authentication Package: NTLM <br/>Workstation Name: Computer_Name <br/>Status code: 0xC000006D <br/>Substatus code: 0x0 <br/>Caller User Name: - <br/>Caller Domain: - <br/>Caller Logon ID: - <br/>Caller Process ID: - <br/>Transited Services: - <br/>Source Network Address: IP_Address <br/>Source Port: Port_Number</span></p> <p><strong>The Cause:</strong> This issue occurs when the web site uses Integrated Authentication and has a name that is mapped to the local loopback address.<br/><br/><a href="http://blogs.technet.com/mdm/archive/2009/11/05/automatic-fixit-you-receive-error-401-1-when-you-browse-a-web-site-that-uses-integrated-authentication-and-is-hosted-on-iis-5-1-or-a-later-version.aspx">http://blogs.technet.com/mdm/archive/2009/11/05/automatic-fixit-you-receive-error-401-1-when-you-browse-a-web-site-that-uses-integrated-authentication-and-is-hosted-on-iis-5-1-or-a-later-version.aspx</a><a href="http://blogs.technet.com/configurationmgr/archive/2009/11/05/automatic-fixit-you-receive-error-401-1-when-you-browse-a-web-site-that-uses-integrated-authentication-and-is-hosted-on-iis-5-1-or-a-later-version.aspx"></a><br/><br/>J.C. Hornbeck | Microsoft</p>Thu, 05 Nov 2009 21:25:37 Z2009-11-05T21:25:37Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/bd2392e4-315f-489d-9e34-0fad351f96f3http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/bd2392e4-315f-489d-9e34-0fad351f96f3Jun1orhttp://social.technet.microsoft.com/Profile/en-US/?user=Jun1orDevice Status/Software Distribution<p>I am trying to push new software down to few device but these are reporting &nbsp;'the device has not reported status in&nbsp;19 or more days'. These devices are not receving the new software. When checking the Device Report the following appears<br /><br /><span style="font-size: xx-small;"><strong>No events are available. This may be because the client has not yet sent the event or the events have been purged from the server. Refer to %WINDIR%\WindowsUpdate.log on Device2.domain.local for details.</strong><br /><br />Where is the windowsupdate.log on the device or server?<br /><br />Previously I was advised to enable alert logger in Status viewer but i can not see this option. I can only see the Menu, Managed programs and managed objects viewer. The connection in Status viewer/MDM connect now is successful.</span></p>Tue, 06 Oct 2009 10:12:59 Z2009-11-05T17:13:39Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/899e921f-1d21-46d6-91f3-9a64427619cchttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/899e921f-1d21-46d6-91f3-9a64427619ccsavaytse66http://social.technet.microsoft.com/Profile/en-US/?user=savaytse66Deploying SCMDM (Enrollment Server) on SBS 2008This might be a non-starter from the outset, but here's what I am trying to do.  I want to install SCMDM on a Small Business Server (SBS2008).  I am having trouble once I get to the point where I install the Enrollment Server, but here are the steps I have taken using this page as a reference http://technet.microsoft.com/en-us/library/dd261786.aspx :<br/> <ol> <li>I followed steps 1a, 1b, and 1d (1c was optional and I believe was done while configuring the AD) to configure the Active Directory.  The only error I encountered was in step 1a, #6 <strong>(<span><strong>/enablegpsecurity), but this step appears to be optional, so I ignored the error and proceeded the rest of the way error-free.</strong> </span> </strong> </li> <li><span>When it comes time to install the Enrollment Server, I get the following Prerequisite error: &quot;The TCP/IP port 443 is in use by another application. The Enrollment Server requires the TCP/IP port 443 for communication with clients.  Stop the application currently using this port and restart the Setup wizard.&quot;  This makes sense considering SBS 2008 has so many roles installed by default, and I use Outlook Web Access, which I believe also uses port 443.</span> </li> </ol> <br/> So what do I do?<br/> <ul> <li>Can the Enrollment Server coexist on port 443?</li> <li>Can I temporarily shut down any applications using port 443, install Enrollment Server, change its default port, and restart the other applications?</li> <li>Can I even continue installation of Enrollment Server on the SBS machine? or am I wasting my time?</li> <li>Other options?</li> </ul> <br/> A few other items to note:<br/> <ul> <li>I use Windows Server 2008 R2 as my host, and I have SBS2008 running on a Hyper-V VM.</li> <li>SBS2008 is set up as the &quot;heart and soul&quot; of my network; it is the primary file server, AD controller, DHCP, DNS, Exchange 2007, etc...it is a typical SBS 2008 setup.</li> <li>I am behind a dynamic IP.  My local domain is mydomain.local, and my internet domain which I use for OWA is mydomain.dyndns.org.  When completing step 1 from the deployment guide (the AD configuration), I used mydomain.local as my FQDN.</li> <li>I've got OWA working fine, my mobile device synchronize quite nicely with Exchange, so on and so forth.  I seem to have a solid, stable setup.</li> </ul> Any insight?<br/> <br/> ThanksThu, 05 Nov 2009 14:06:12 Z2009-11-09T06:20:13Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/fd917fe4-22c8-46bb-bcd6-63d21393a2bahttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/fd917fe4-22c8-46bb-bcd6-63d21393a2baWindCloudhttp://social.technet.microsoft.com/Profile/en-US/?user=WindCloudEmail Filtering Feature For SCMDMHi,<br/><br/>Is there any way to filter &quot;encrytped&quot; email messages from MDM server before it send to the mobile device user? <br/><br/>Thanks.<br/>KCWed, 28 Oct 2009 08:50:59 Z2009-11-09T00:13:10Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/1017c4bb-95e6-4eac-933b-7d61dbac02d8http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/1017c4bb-95e6-4eac-933b-7d61dbac02d8NeilJaxxhttp://social.technet.microsoft.com/Profile/en-US/?user=NeilJaxxCmdlet Get-DeviceManagementConfigHi,<br/><br/> I can't seem to find an answer to this question so I'll post to the group. I have been looking at the MDM Powershell cmdlet called Get-DeviceManagementConfig. In particular I'm looking at parameters:<br/><br/> PurgeInterval and EnablePurge.<br/><br/> By default Microsoft have set these to:<br/><br/> PurgeInterval = 373 days and EnablePurge = True.<br/><br/> Now looking at the technet info, this has me confused - as follows:<br/><br/> EnablePurge<br/> Specifies whether PurgeInterval is enabled. If set to $true, then a device is removed from the Device Registration database after a period of time defined by the PurgeInterval value. If set to $false, then devices are not automatically removed from the Device Registration database. The default value is $true.<br/><br/> PurgeInterval<br/> Specifies the length of time after which devices that are no longer enrolled are completely removed from the Device Registration database. The value may range from one day to 3660 days. The default value is 373 days. If the value contains a space or other special characters, enclose the string in quotation marks.<br/><br/> My question is, does this only apply to blocked / wiped devices or all working devices aswell? Does this mean a device will be removed from the registration database (or expire) after 373 days, even if there is nothing wrong with it?<br/><br/> Sorry if I've missed the obvious or if I'm being a bit thick!<br/><br/> Neil.<br/><br/> Tue, 08 Sep 2009 13:26:58 Z2009-11-01T22:23:50Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/e0b0e058-f125-454b-8431-5007946ba3bbhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/e0b0e058-f125-454b-8431-5007946ba3bbmartin_hansenhttp://social.technet.microsoft.com/Profile/en-US/?user=martin_hansenimporting personal certificateHello,<br/> <br/> can I import a personal certificate to a Windows Mobile device in a way that the private key will be marked as &quot;non exportable&quot;? Otherwise, if the device gets lost, any unauthorized person can export the private key then. <br/> <br/> there are flags <span><span><span class=srcSentence>CRYPT_EXPORTABLE and </span> </span> </span> <span><span><span class=srcSentence>CRYPT_USER_PROTECTED <a href="http://msdn.microsoft.com/en-us/library/aa924245.aspx">http://msdn.microsoft.com/en-us/library/aa924245.aspx </a> <br/> If someone knows if these flags in </span> </span> </span> <span><span><span class=srcSentence>PFXImportCertStore</span> </span> </span> <span><span><span class=srcSentence>are set or not that would help me a lot<br/> Unfortunately the Windows Mobile UI does not offer to set these flags during the certificate import process</span> </span> </span> <br/> <br/> MartinSun, 01 Nov 2009 14:22:42 Z2009-11-09T00:14:42Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/8b7cf4ff-a76f-4a6d-b6cd-f6c474c67923http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/8b7cf4ff-a76f-4a6d-b6cd-f6c474c67923GforumBhttp://social.technet.microsoft.com/Profile/en-US/?user=GforumBMDM support of CNG and keylengthDoes the latest version of MDM support CNG provider (using WS08 R2 PKI) and what is the maximum key length it supports?<br/>Thu, 29 Oct 2009 13:32:28 Z2009-11-10T14:41:42Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/e7852584-f866-4c01-83d4-574659116bd6http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/e7852584-f866-4c01-83d4-574659116bd6jbuszardhttp://social.technet.microsoft.com/Profile/en-US/?user=jbuszardproblems connecting after enrollment<p>in our org we are running MDMSP1 and have recently enrolled a large number of devices - the majority of which appear to be working fine.<br />however there are some that have successfully enrolled OK but then are unable to connect.<br />using the VPN diagnostic tool on the device it comes up with the reason as 'Root certificate does not exist'<br />i'm happy the connection works OK as its the same connection settings as other devices and i've tried re-adding those but to no avail.<br /><br />anyone have any ideas what would cause this?</p>Tue, 06 Oct 2009 12:23:01 Z2009-10-29T09:27:27Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/bc17fbef-e9cb-4833-99ee-ed9606e0937ehttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/bc17fbef-e9cb-4833-99ee-ed9606e0937eym81http://social.technet.microsoft.com/Profile/en-US/?user=ym81different activesync policies for different devices belonging to same userHi,<br/>   Using SCMDM, I can specified whether a user can download emails and/or attachments to his mobile device.  This is done by applying a user (not device) policy to that user.<br/> <br/>   I have a requirement such that a user has 2 mobile devices.  PDA A is self-owned while PDA B is company-issued.  The user is only supposed to sync calendar events and not emails to PDA A.  But he can sync all emails, task, calendar to PDA B.<br/> <br/>   Given that the a user would have only 1 MS Exchange mailbox and the activesync policy is applied on the user and not device, how can I achieve this?  Pls advise.<br/> <br/>   Thanks.<br/> <br/> Regards.Wed, 28 Oct 2009 02:19:38 Z2009-10-29T01:42:53Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/4e3ac5cb-1e13-4c2e-ba66-cf9e38da3936http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/4e3ac5cb-1e13-4c2e-ba66-cf9e38da3936Logan.B.http://social.technet.microsoft.com/Profile/en-US/?user=Logan.B.MDM Enrollment serverHi<br/><br/>I have installed enrollment server.After successful installation i got only help file in my start program files ? How do i start accessing the enrollment server.<br/><br/>Also if i go to IIS webpage i am getting HTTP Error 403.4 - Forbidden: SSL is required to view this resource<br/><br/>Please let me know how do i proceed on this ?<br/><br/>Regards<br/>Loganathan.bThu, 30 Jul 2009 15:58:13 Z2009-11-09T23:24:37Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/ee782b69-2705-45ea-83e0-e49349fafc7bhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/ee782b69-2705-45ea-83e0-e49349fafc7bLogan.B.http://social.technet.microsoft.com/Profile/en-US/?user=Logan.B.BPA Error<table style="font-size:12px;font-family:Sans-Serif" border=0 width="100%"> <tbody> <tr> <td width="50%" align=left> <p>Hi,<br/><br/>I am getting below error when i am running BPA for scmdm 2008 ?</p> <p>I am able to access the site and i am getting certificate warnings etc ? what could be a problem ?<br/>Unable to connect to MDM Device Management Administration Web site.<br/>Make sure that the certificate for the newly created Device Management Administration Web site for MDM Device Management Server is valid and the Web site is running. Obtain certificates for the site if it is necessary. See Deployment Guide for System Center Mobile Device Manager 2008 . <br/></p> </td> </tr> <tr> <td width="10%"><img src="http://social.technet.microsoft.com/images/shield_red.gif" alt=Error align=center></td> <td width="50%" align=left>Unable to connect to MDM Device Management Web site. <br/>Make sure that the certificate for the newly created Device Management Administration Web site for MDM Device Management Server is valid and the website is running. Obtain certificates for the site if it is necessary. See Deployment Guide for System Center Mobile Device Manager 2008 . <br/><br/></td> </tr> </tbody> </table>Thu, 06 Aug 2009 10:11:52 Z2009-10-28T23:56:40Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/d7092516-8450-4580-b45c-c9cd22cb4f8dhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/d7092516-8450-4580-b45c-c9cd22cb4f8dnowiresmatthttp://social.technet.microsoft.com/Profile/en-US/?user=nowiresmattMobile Device Factory Wipe on a single failed password<p>We have had a situation reported where a device has performed a factory wipe on a single failed password or not at all.&nbsp; This has been reported on two different devices HTC Touch Pro2 and an HTC Diamond 2 running 6.1.4 (latest production release).&nbsp; Normally I would say the user was mistaken however I have just watched exactly the same this happen in front of me on an HTC Mega Mobile 6.5.<br />The group policy appplied for passwords is Simple Password, 4 characters, 10 attempts prior to wipe, "SCMDM 2007" prompt on attempt 7.<br /><br />What has just happened is the HTC Mega was on my table and not connecting to the 3G network due to a SIM issue - ie no phone, no wifi, no 3g.&nbsp; The device was attempting to connect regularly then all of the sudden the screen becomes active and the you have one more attempt to logon prior to a wipe appears.&nbsp; To be clear there have been no logon attempts and no failed logons at all since enrollment on this device.&nbsp; <br /><br />I then entered the password incorrectly and the factory wipe proceeded.&nbsp;<br /><br />So this thing has wiped on a single incorrect password even though the group policy was for 10 attempts.&nbsp; The word prompt did not occur.&nbsp; The user was simply presented with the 1 logon left message without attempting to logon...<br /><br />This is a disaster.&nbsp; Has anyone else seen this?&nbsp; I'm going to try and replicate on 6.1 , 6.5 devices but would be interested if anyone has seen this occur.<br /><br />The only common thing I see at the moment is that the devices may not have had network coverage and be retrying prior to this occuring.<br /><br />This is a real pain to debug as a factory wipe is performed so any local logs are toast as encryption is on so even cards are unless due to encryption.&nbsp; I'll have to try without encryption on.&nbsp; Any suggestions as to how to debug this one?<br /><br />Cheers<br /><br />Matthew</p>Fri, 09 Oct 2009 10:25:47 Z2009-11-01T22:14:03Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/e6feee22-a509-412b-88c6-ffd8ed6beca9http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/e6feee22-a509-412b-88c6-ffd8ed6beca9Thatguy213http://social.technet.microsoft.com/Profile/en-US/?user=Thatguy213HP touchpad issues, againI have a factory Pavillion DV4-1220us, and am unable to get the touchpad to work. As usual, HP support said to do a full recovery, and that is really not an option here. I have done a sys. restore, and have reinstalled the driver for it(I think it was the right one). I could care less about the volume controls, but I cannot turn on my wireless without it. Any body got a sollution or some advice?Tue, 27 Oct 2009 18:32:01 Z2009-11-01T22:13:17Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/45ee0dbb-c09f-42c5-99ba-f37181319509http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/45ee0dbb-c09f-42c5-99ba-f37181319509Ras11mhttp://social.technet.microsoft.com/Profile/en-US/?user=Ras11mISA Server and SSL reverse proxy for mobile enrollement Hi there Guys,<br/><br/>We have got an existing ISA 2006 server with single IP address (DMZ subnet), is it possible to utilisie reverse proxy capabilities of this box for enrollment. Please bear in mind that This server is also used as a proxy for internal clients. If so what would be the best way to go about it ? <br/><br/>I.e can i get the external firewall to forward SSL traffic to ISA and configure the publising rule and open 443 from isa to mdm enrollment server? <br/><br/>What i am trying to get to is whether or not we need dual nics on the ISA server?  <br/><br/>Best Regards,<br/><br/>RasMon, 26 Oct 2009 03:57:00 Z2009-11-01T22:14:47Zhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/1481ad66-fb09-4aff-a024-ee76ce3c3e1fhttp://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/1481ad66-fb09-4aff-a024-ee76ce3c3e1fJulie Hasletthttp://social.technet.microsoft.com/Profile/en-US/?user=Julie%20HaslettISA Server and SSL Confogiration Hi, my company is the process of configuring our MDM which uses ISA server to publish the mobileenroll.domain.com.<br><br>The question I have is, do we terminate the SSL connection at the ISA Server, and pass non-SSL traffic to the Enrollment Server, or do we set the ISA Server to pass-through mode and put the SSL certificate on the Enrollment Server?<br><br>Thanks, Julie<br><br>Mon, 29 Sep 2008 17:24:09 Z2009-10-30T05:16:04Z