Answered by:
Secondary Site vs. Distribution Point for untrusted domain

Question
-
hello, I want to migrate from sccm 2007 to 2012 and wonder how to manage this :
I have 8 untrusted AD with less than 100 clients (hosted servers for external companies ).
Actually the sccm 2007 design is -
a central primary site in the corporate domain
8 child primary sites (one in each untrusted domain) - Firewall between the untrusted domains and corporate domain allowing only the child site server to talk with the corporate site.
I think that a site for less than 100 machines is overwhelming, so I wonder if I can achive the same goal with only a DP with the MP role
but I read that it is not possible to "assign" a mp to a set of client only - so maybe impossible to avoid corporate client trying to talk to the MP in untrusted domain?
Security doesn't want to open firewall for all clients in untrusted site to Talk to the corporate MP.
So is it possible with a secondary site ? (but I read :you can't have a hierachy spanning untrusted domains/Forest in 2012. Only site systems (not sites) can be deployed in untrusted forests/domains).
Is there another solution , or Am I missing something ?
Thanks in advance
Eric Delmotte
- Edited by EricBelgacom Friday, February 1, 2013 4:54 PM
Friday, February 1, 2013 4:53 PM
Answers
-
Thanks :
this one is exactly what I was looking for :
Eric Delmotte
- Marked as answer by EricBelgacom Monday, February 4, 2013 12:41 PM
Monday, February 4, 2013 12:41 PM
All replies
-
Like you said you cannot have a primary/secondary in an untrusted forest. You can only place user facing site system roles in untrusted forest. You will need to place a MP/DP in each untrusted forest where you need to manage clients. You will need to publish to the system management container of the untrusted forest this will be how client in the untrusted forest find the MP (This is described in the first link)
For a guide view:
http://blog.coretech.dk/kea/multi-forest-support-in-configmgr-2012-part-i-managing-clients-in-an-untrusted-forest/http://technet.microsoft.com/en-us/library/bb694003.aspx
Justin Chalfant | Blog: setupconfigmgr.com | SCUP Catalog: patchmypc.net/scup | Please mark as helpful/answer if this resovled your issue
- Edited by Justin Chalfant Friday, February 1, 2013 6:16 PM
- Proposed as answer by Justin Chalfant Monday, February 4, 2013 1:22 PM
Friday, February 1, 2013 6:12 PM -
Thanks :
this one is exactly what I was looking for :
Eric Delmotte
- Marked as answer by EricBelgacom Monday, February 4, 2013 12:41 PM
Monday, February 4, 2013 12:41 PM