Fact-checked by Grok 2 weeks ago

Microsoft Configuration Manager

Microsoft Configuration Manager is a comprehensive systems management solution developed by , designed to help IT administrators manage devices, applications, and across on-premises, , and hybrid environments. It enables the deployment of operating systems, software updates, and applications; enforces compliance policies; monitors system health; and provides detailed inventory reporting for large-scale Windows deployments, with macOS support via co-management with and limited capabilities for servers. As part of the suite, it supports secure and scalable operations by integrating with tools like , (WSUS), and , reducing manual tasks and optimizing resource utilization. Originally introduced as Systems Management Server (SMS) in 1994 to address software distribution and inventory needs in enterprise networks, the product evolved significantly over the decades. In 2007, it was rebranded as System Center Configuration Manager (SCCM) to align with the broader System Center portfolio, introducing advanced features like desired state configuration and enhanced endpoint protection integration. The platform shifted to a current branch servicing model in 2016, allowing frequent updates without full version upgrades, and was renamed Microsoft Endpoint Configuration Manager (MECM) around 2020 as part of the Microsoft Endpoint Manager initiative, emphasizing cloud-hybrid capabilities alongside Microsoft Intune. In March 2023 with version 2303, it received its current name, Microsoft Configuration Manager, to simplify branding while maintaining backward compatibility and support for existing deployments. Key features include the Configuration Manager console for centralized administration, Software Center for end-user self-service, and cloud-attached management options that enable co-management with Intune for modern endpoint scenarios. It supports real-time analytics, remote actions on devices, and integration with Defender for Endpoint to enhance security posture. As of November 2025, the product follows an annual release cadence starting with version 2609, focusing on security enhancements and streamlined servicing to meet evolving enterprise needs.

History

Origins as Systems Management Server

Microsoft Systems Management Server (SMS) 1.0 was launched on November 7, 1994, marking Microsoft's inaugural enterprise management tool designed specifically for Windows NT networks. Development began in 1992 with a small team of two engineers and an intern, taking over two years to complete the initial release, which aligned with the build numbering of Windows NT Server 3.5. This product emerged as a foundational solution for IT administrators seeking to oversee environments amid the rapid proliferation of personal computers in corporate settings. The creation of SMS 1.0 responded to the escalating demands for centralized management in client-server architectures following the widespread adoption of Windows 3.1. As organizations transitioned from mainframe-based terminal emulation to x86-based distributed systems, there was a critical gap in tools capable of scaling PC management across enterprises. Built on Server 3.5, SMS 1.0 supported a diverse array of clients including , Windows, , Macintosh, and , while integrating with networks such as , , and Pathworks. Key features of SMS 1.0 included , which utilized a drag-and-drop to and remotely install software and packages across the network. Inventory collection automatically gathered hardware and software enterprise-wide, enabling hierarchical domain support for . Remote control capabilities allowed administrators to execute programs, update configurations, and perform directly from the server. Early adoption of SMS 1.0 faced challenges due to its initial limitation to () environments, lacking support for wide area networks (WANs) and thus restricting in geographically dispersed setups. Despite this, the tool demonstrated potential for managing tens of thousands of PCs, with endorsements from 25 third-party vendors including , , and at launch.

Transition to Systems Center Configuration Manager

In 2007, Microsoft rebranded its Systems Management Server (SMS) 2003 product as System Center Configuration Manager (SCCM) 2007, marking a significant evolution in enterprise tools. Released on November 29, 2007, SCCM 2007 introduced native mode operations, which provided deeper integration with for enhanced authentication, site publishing, and discovery services, as well as seamless compatibility with (WSUS) for streamlined software update management. This shift addressed limitations in the legacy mixed-mode operations of SMS, enabling more secure and efficient management of distributed environments supporting and Windows Server 2008. The rebranding to SCCM aligned the product with Microsoft's emerging System Center family, which aimed to deliver a unified portfolio for IT infrastructure management, including tools like Operations Manager and Virtual Machine Manager. By emphasizing over general , the name change reflected a strategic focus on desired state management and broader ecosystem integration, facilitating easier adoption within heterogeneous enterprise settings. This alignment helped position SCCM as a core component for holistic IT operations, reducing silos between server, client, and . Subsequent enhancements in SCCM 2007, particularly through the release in 2009, expanded support for virtualization technologies, including integration with Application Virtualization (App-V) for streaming virtualized applications to endpoints without full installation. These updates improved scalability for virtual environments by enabling efficient deployment and management of sequenced applications, alongside features like via for remote hardware control. Service Pack 2 in 2009 further bolstered support for and , enhancing overall performance and security. The transition culminated in major milestones with SCCM 2012, released in 2012, which introduced role-based administration (RBA) for granular security control across hierarchies, the application model for user-centric software delivery with supersedence and revision tracking, and initial cloud attachments via integration with Windows Intune for hybrid management scenarios. Service Pack 1 in 2013 added support for mobile device management and enhanced cloud proxy features, while Service Pack 2 in 2015 refined scalability for large-scale deployments. These advancements solidified SCCM's role in bridging on-premises and emerging cloud-based IT strategies.

Modern Evolutions and Integrations

In 2016, introduced the Current Branch servicing model for Configuration Manager, enabling faster delivery of new features through semi-annual updates rather than infrequent major releases. This shift allowed administrators to adopt enhancements more rapidly while maintaining stability, with the model becoming available to customers with active Software Assurance rights starting October 1, 2016. Notable releases under this model include version 1806, which improved application management and integrations, and version 1910, which enhanced and compliance tools. The product underwent a significant in 2019 to Microsoft Endpoint Configuration Manager, reflecting its evolving focus on across environments. This change, first appearing in version 1910, aligned the tool more closely with Microsoft's broader strategy, emphasizing device-centric capabilities over traditional . Throughout the 2020s, key developments centered on enhanced co-management with , allowing seamless workload shifting between on-premises and cloud-based for and later devices. This integration, which matured with updates like version 2103 for improved scenarios and version 2203 for advanced compliance reporting, enables organizations to leverage Intune for while retaining Configuration Manager for complex deployments. Support for was added starting in version 2107, including client installation on ARM64 devices and OS deployment capabilities, with further refinements in version 2403 for full ARM64 task sequences. Additionally, Configuration Manager facilitates modern workload deployments, such as the desktop client, through application packaging and bulk installation methods that integrate with Apps updates. By 2025, integrations with Purview advanced compliance management, particularly through device onboarding for endpoint data loss prevention on Windows 10/11 and macOS devices managed via Configuration Manager. Version 2403 and subsequent releases introduced analytics, including an automated diagnostic dashboard for software update health that monitors deployment issues and provides proactive insights to reduce troubleshooting time. These evolutions underscore Configuration Manager's alignment with Microsoft's endpoint ecosystem, supporting hybrid cloud strategies amid the announced transition to an annual release cadence starting with version 2609.

Architecture and Components

Core Site Infrastructure

The core site infrastructure of Microsoft Configuration Manager consists of server-side components that enable centralized management of devices and applications across an organization. These elements form the foundational backbone, handling , , and client interactions within a site's . Primary and secondary site servers provide the structural core, while site system roles such as distribution points and management points support operational efficiency by managing delivery and communication flows. The primary site server serves as the central hub for a Configuration Manager site, hosting essential services and the site database. This database, built on , stores all site-specific data, including configuration settings, inventory information, and deployment details, ensuring reliable access and management for the site's resources. The SMS Provider, a key component on the primary site server, acts as the for site data storage and retrieval, allowing administrative tools like the Configuration Manager console to interact with the database securely. Primary sites can operate as stand-alone entities for smaller deployments or as child sites within a larger , supporting direct management of up to hundreds of thousands of clients depending on scale. Secondary site servers extend the reach of a primary site into distributed or remote environments, particularly where network links are slow or unreliable, by managing a subset of clients without replicating the full primary site database. Installed as child sites beneath a primary site, they use a lightweight local database—typically —to handle local operations, compressing data transfers to the parent site for efficiency. This setup reduces bandwidth usage and latency for remote management tasks, with secondary sites automatically including default roles like distribution points for localized support. Each primary site can support up to 250 secondary sites, making them suitable for large, geographically dispersed organizations. Distribution points (DPs) are dedicated site system servers responsible for storing and delivering content, such as software packages, updates, and operating system images, to managed clients. Content is replicated from the site server to via or methods, with organizing files in a content library to optimize storage and access. In cloud-integrated scenarios, pull distribution points enable to fetch content from source , reducing administrative overhead and supporting hybrid environments like . can be configured with features like PXE booting for automated deployments and for secure delivery, and boundary groups direct clients to the nearest available to minimize network traffic. Management points (MPs) facilitate communication between clients and the site infrastructure, serving as the primary endpoint for policy retrieval and data submission. Clients connect to an MP to receive assigned policies, such as software deployment instructions, and to upload inventory and status data, which the MP then forwards to the site database. MPs support HTTPS communication for enhanced security and can use database replicas to offload query processing from the primary database server, improving performance in high-volume environments. Installed by default on primary and secondary site servers, additional MPs can be added to handle load balancing, with each primary site supporting up to 15 instances.

Client-Side Components

The Configuration Manager client agent is the primary software component installed on managed devices, enabling them to communicate with site servers, retrieve policies, and execute management tasks. This agent runs as the SMS Agent Host service, implemented by the executable ccmexec.exe, which relies on (WMI) for core operations such as policy evaluation and enforcement. The service hosts various client-side processes, including those for inventory collection and , ensuring devices remain compliant with organizational policies. Client push installation is a common method for deploying the Configuration Manager client to Windows devices, where the site server automatically discovers eligible computers through integration and initiates the installation without manual intervention. This process uses the CCMSetup.exe installer, which can be configured with parameters to specify site assignment and management points during setup. Alternatively, manual installation allows administrators to run CCMSetup.exe directly on devices, providing flexibility for environments without discovery. Key client-side components include the Client Location Services, which enable devices to identify and connect to appropriate site system roles, such as management points, by querying for site resources based on location and boundary groups. The Hardware Inventory Agent, another essential component, periodically collects detailed hardware configuration data from devices—such as , , and disk information—and reports it back to the site server via WMI queries, supporting without requiring additional software. These components operate under the ccmexec.exe service to minimize resource overhead while maintaining real-time communication.

Hierarchical Site Structure

Microsoft Configuration Manager employs a hierarchical site structure to enable scalable management across large, geographically distributed environments, allowing organizations to interconnect multiple sites for centralized oversight and efficient data flow. This topology supports deployments ranging from a single standalone primary site to complex hierarchies with a site (CAS) at the top level, overseeing child sites to handle global policies, reporting, and resource distribution. The central administration site serves as the top-tier component in multi-site hierarchies, designed to manage and monitor multiple primary sites without directly handling client devices or roles such as points. It coordinates hierarchy-wide configurations, including policy enforcement and aggregated reporting from all child sites, ensuring consistent administration across the organization. For instance, the replicates global data like software deployments and collection definitions to all sites, facilitating unified in enterprises with thousands of devices. Parent-child relationships form the backbone of the , establishing bidirectional replication between to synchronize essential such as boundaries, collections, and configurations. In this model, a acts as the to up to 25 primary sites, while each primary site can multiple secondary sites to extend coverage to remote locations. Replication occurs via SQL Server, using change tracking and the Service Broker on port 4022 to merge updates bidirectionally; global propagates downward to all sites, site-specific like flows upward to parents, and content uses file-based methods for secondary sites over low-bandwidth links. This ensures consistency without overwhelming network resources, with initial snapshots transferred via SQL Server Bulk Copy Program. Boundary groups enhance the hierarchical structure by logically organizing network boundaries—such as IP subnets or Active Directory sites—to define client assignment and resource access across sites. These groups associate boundaries with site system roles like distribution points (DPs) for content delivery and management points (MPs) for communication, allowing clients to efficiently locate nearby resources and reducing WAN traffic in multi-site setups. In a hierarchy, boundary groups can overlap and include fallback options, enabling clients to request services from preferred or adjacent sites as needed. Scaling considerations in the emphasize and limits to support expansive deployments. A single can oversee up to 25 primary sites, each managing up to 250 secondary sites, with SQL Server replication optimizing data transfer to maintain efficiency in large-scale environments. Organizations must topologies based on count, geography, and , often starting with a standalone primary site and expanding to include a as needs grow beyond 175,000 clients.

Features and Capabilities

Software Distribution and Patching

Microsoft Configuration Manager facilitates software distribution and patching by enabling administrators to deploy applications, updates, and operating systems to managed endpoints across an . This relies on a centralized console for creating, distributing, and enforcing software deployments to device or user collections, ensuring consistency and compliance with organizational policies. Content, such as installers or update files, is first packaged and sent to distribution points—servers that store and serve files to clients—before clients download and install them based on assigned schedules or user interactions via Software Center. The application model in Configuration Manager supports modern deployment of software using or MSIX formats, allowing for flexible packaging that includes multiple deployment types per application. Administrators define detection methods, such as file existence, registry keys, or scripts, to verify if an application is already installed on a target , preventing unnecessary redeployments. Requirements can specify conditions like operating system version, , or free disk space before installation proceeds. Supersedence rules enable automatic upgrades by designating newer application versions to replace older ones, streamlining version management without manual intervention. Unlike packages, which offer basic script-based installations, the application model provides advanced features like simulation testing and user-friendly notifications in Software Center. For patching, Configuration Manager integrates the Software Update Point (SUP) with (WSUS) to synchronize and manage software s from Microsoft or upstream servers. The SUP, installed on a site system server, retrieves metadata during scheduled synchronizations—typically daily—and replicates it across the hierarchy for child sites. Clients scan for compliance using this metadata, reporting states like "Required" or "Installed" back to the management point, which administrators can monitor for deployment planning. Deployment Rules (ADRs) automate the patching process by evaluating criteria such as classification, product, and severity to create software update groups, download content to distribution points, and deploy to targeted collections on a recurring schedule, such as monthly for releases. This reduces administrative overhead while enforcing deadlines and maintenance windows to minimize disruptions. Task sequences in Configuration Manager automate complex workflows, including operating system (OS) deployment and custom scripting, by sequencing steps like partitioning disks, applying images, and installing drivers or applications. For OS deployment, administrators create task sequences that capture user state, format drives, and deploy Windows images from distribution points, with options to customize via variables for site-specific configurations. Integration with Deployment Toolkit (MDT) enhances these sequences through a that adds advanced steps for application deployment, management, and post-install scripting, enabling zero-touch installations without user intervention. Custom scripts, such as or , can be embedded to handle tasks like joining domains or configuring settings, making task sequences versatile for both initial setups and in-place upgrades. To optimize bandwidth usage during distribution and patching, Configuration Manager leverages Delivery Optimization, a peer-to-peer protocol built into and later, which allows clients to share content directly with nearby devices on the same or across subnets using Group IDs derived from boundary groups. This reduces internet or WAN traffic by sourcing up to 100% of content from peers when available, falling back to distribution points or Microsoft Update as needed. Cloud-based delivery further enhances efficiency by enabling global peering through the Delivery Optimization service, particularly for express installation files (deltas) in updates, minimizing download sizes and supporting throttled transfers during off-peak hours. Administrators configure these settings via client policies to balance performance and network load.

Inventory and Asset Management

Microsoft Configuration Manager's hardware inventory feature collects detailed information about the physical and logical components of managed client devices by querying (WMI) classes and the . This process captures data such as (CPU) details including model and speed, (RAM) capacity and type, and information like size and free space on logical drives. The inventory runs on a configurable schedule, typically every seven days by default, and clients report the data to the site's management point, which then stores it in the Configuration Manager database for centralized access and analysis. Administrators can extend hardware inventory beyond the standard classes by modifying the configuration.mof file on the top-level site server, which defines the WMI queries used for . This customization allows the inclusion of additional hardware attributes not covered in the default , such as specific peripherals or custom device properties, by adding new WMI references to the MOF and ensuring the corresponding classes exist on client devices through software updates or extensions. After modification, the site rebuilds the policy, and clients incorporate the new queries in subsequent cycles, enabling tailored without altering core functionality. Software in Manager focuses on identifying and cataloging s and applications on client devices through systematic scanning and registry . The scans specified types—defaulting to s (*.exe)—across local drives and reads registry keys to detect installed applications, capturing details like versions, sizes, and paths. occurs via client settings, where administrators define schedules, types to include or exclude, and optional collection rules to copy detected s to a network share for further ; subsequent scans report only changes (delta ) to optimize bandwidth. This data integrates into the site database, providing visibility into software deployments across the environment. Asset Intelligence enhances inventory capabilities by synchronizing with Microsoft's online catalog to classify inventoried software and manage licensing compliance. Enabled through an Asset Intelligence synchronization point, the feature downloads updates over HTTPS (TCP port 443) on a scheduled or on-demand basis, applying predefined categories, families, and labels to over 300,000 software titles for standardized reporting. Administrators can import license agreements into the database to reconcile against usage data, generating reports on license compliance and overutilization; custom software titles may be uploaded to Microsoft for review and categorization. The Asset Intelligence synchronization point and the ability to synchronize with Microsoft's online catalog have been deprecated since November 2021 and are no longer supported as of November 2022. However, the Asset Intelligence hardware inventory classes and reporting features using them remain supported. Collections in Configuration Manager serve as logical groupings of devices and users based on inventory data, facilitating targeted management tasks such as software deployments. Static collections require manual addition of members, maintaining fixed membership until explicitly updated, which suits stable groups like department-specific servers. In contrast, dynamic collections use query-based rules—drawing from hardware, software, or attributes—to automatically populate and refresh membership on a schedule, often every five minutes with incremental updates, ideal for evolving sets like all devices with insufficient . These collections enable precise targeting without referencing distribution mechanisms directly.

Compliance and Endpoint Protection

Microsoft Endpoint Configuration Manager provides compliance settings to enforce desired configurations on managed devices, ensuring adherence to organizational policies through configuration baselines and items. Configuration baselines group one or more configuration items (CIs), which define specific settings and compliance rules for platforms like Windows and macOS. These CIs support checks for registry keys, file properties, and custom scripts to verify compliance, allowing administrators to assess whether devices meet predefined standards such as security configurations or software requirements. For instance, a CI might validate the presence of a specific registry value or the integrity of a critical file, reporting deviations as noncompliant. Compliance settings enable remediation actions for noncompliant devices, where applicable rules can automatically correct issues, such as resetting a registry entry or running a script to enforce the desired state. Evaluation schedules determine how frequently clients assess baselines, with results reported back to the site server via state messages; by default, these evaluations occur on a configurable interval, such as daily, and can be customized in client settings to balance thoroughness with resource usage. Administrators compliance through the Configuration Manager console's Monitoring workspace or built-in reports, identifying noncompliant assets for targeted remediation. This process integrates briefly with inventory data to contextualize against collected device attributes. Endpoint Protection in Configuration Manager integrates with to deliver real-time protection against on managed Windows devices. This integration allows for the creation and deployment of antimalware policies that configure scan settings, real-time monitoring, and behavioral analysis to detect and block s like viruses, , and rootkits. Policies can be applied to device collections, enabling centralized management of features such as on-access scanning and network protection through the Windows . Definition updates for are handled via Configuration Manager's software update infrastructure or direct downloads from the Microsoft Protection Center, ensuring timely protection across the hierarchy. Monitoring of Endpoint Protection status occurs in the console's Security node, providing dashboards for detections and adherence. Role-based access control (RBAC) in Configuration Manager secures and endpoint protection features by defining granular permissions through roles, scopes, and collections. Built-in roles, such as the , grant permissions like Read, Create, and Modify for baselines and antimalware policies, while custom roles can be tailored for specific tasks. scopes limit visibility and access to securable objects, such as baselines or endpoint protection points, allowing delegated administrators to manage only assigned resources without full hierarchy access. For example, an admin might be scoped to a particular collection of devices for , promoting secure in large environments. Auditing of RBAC assignments ensures for changes to these .

Deployment and Configuration

System and Hardware Requirements

Microsoft Configuration Manager (ConfigMgr) requires specific hardware and software configurations for its site servers, database servers, clients, and supporting infrastructure to ensure reliable operation and scalability. Site servers, which host core ConfigMgr roles, demand robust resources, particularly when collocated with the site database. For a stand-alone primary site with a collocated SQL Server instance, Microsoft recommends a minimum of 16 CPU cores and 96 GB of RAM, with 80% of the RAM allocated to SQL Server for optimal performance. When the SQL Server is remote, the site server requirements decrease to 8 CPU cores and 16 GB of RAM. Disk space for the site server should start at 50 GB for applications and logs, scaling up to 200 GB for environments with 100,000 clients, while the database file (.mdf) requires approximately 75 GB per 25,000 clients, potentially reaching 2 TB for 700,000 clients. The site database, hosted on SQL Server, is a critical component that influences overall system performance. Supported SQL Server versions include 2022 (Standard/Enterprise), 2019 (CU5 or later), 2017 (CU2 or higher), and 2016 (with required service packs and CUs), with Express edition suitable only for secondary sites. For remote SQL Server deployments on primary sites, recommendations include 16 CPU cores and 72-96 of RAM, with up to 90% allocated to SQL Server. In large hierarchies supporting over 50,000 devices, an edition of SQL Server is required to handle the scale, as edition limits capacity to 50,000 devices. Log files (.ldf) need about 25 per 25,000 clients. All site system servers must run on 64-bit operating systems. Client devices must meet minimum software prerequisites to install and operate the ConfigMgr client. Supported client operating systems include (version 21H2 and later), and later), Windows Server 2025 (Standard, Datacenter, IoT editions since ConfigMgr version 2409), (since version 2107), , and Windows Server 2016. The client requires Microsoft .NET Framework version 4.6.2 or later (4.8 recommended), along with at least 500 MB of free disk space; a 5 GB cache is recommended for content storage. For optional features like OS deployment, clients need an additional 384 MB of . Hardware for the Configuration Manager console includes an i3 or equivalent CPU, 2 GB of , and 2 GB of disk space, with a minimum of 1024x768. Network infrastructure must support secure and efficient communication for ConfigMgr operations, especially in hybrid or cloud-integrated environments. communication is required for distribution points when using enhanced security features, and for cloud management gateway or co-management with . considerations are essential for content replication and client downloads; ConfigMgr provides throttling controls via BITS () to limit usage, but initial content distribution to distribution points can consume significant network resources, with recommendations to plan for at least 100 Mbps links between sites in large deployments. endpoints must be allowed through firewalls for features like software updates and cloud services.
ComponentMinimum CPUMinimum RAMDisk Space NotesScaling for Large Sites (>100,000 Clients)
Site Server (Collocated SQL)16 cores96 GB (80% to SQL)50 GB app/logs; 75 GB/25k clients for DBUp to 128 GB RAM for CAS; 2 TB DB
Remote SQL Server16 cores72-96 GB (90% to SQL)300 GB .mdf for 100k clients; 25 GB .ldf/25k clientsEnterprise SQL required; additional cores/RAM
Distribution Point2 cores8 GBVaries by content (e.g., 500 GB+ for OS images)Multiple DPs
ClientOS-dependentOS + 384 MB (OS deploy)500 MB min; 5 GB cache recommendedN/A
ConsoleIntel i3 equivalent2 GB2 GBN/A

Installation Processes

Installing Microsoft Configuration Manager (ConfigMgr) requires completing several prerequisite steps to ensure compatibility and proper functionality across Active Directory, database, and update services. The Active Directory (AD) schema must be extended to support ConfigMgr's discovery and client communication features. This extension adds necessary objects and attributes to the AD forest, performed once per forest. To extend the schema, use an account that is a member of the Schema Admins group on the schema master domain controller. Run extadsch.exe from the SMSSETUP\BIN\X64 folder on the installation media; this tool automatically applies the schema changes. Alternatively, import the ConfigMgr_ad_schema.ldf file using ldifde -i -f ConfigMgr_ad_schema.ldf -v -j "%temp%" after editing the domain components in the file. Verify success by checking the extadsch.log file in the system drive root or the LDIFDE log in the temp directory. After extension, create the System Management container in each domain using ADSI Edit (adsiedit.msc), granting full control to the site server computer account. SQL Server setup is another critical prerequisite, as ConfigMgr sites rely on a supported SQL instance to host the site database. Supported versions include SQL Server 2022 (Standard or Enterprise editions, compatibility level 150), SQL Server 2019 (CU5 or later), SQL Server 2017 (CU2 or higher), and SQL Server 2016 (with required service packs and CUs). Use a 64-bit instance with , SQL_Latin1_General_CP1_CI_AS , and features like Services enabled. Install SQL Server on the site or a remote dedicated , configuring it with at least 8 GB for central or primary sites (50-80% max memory allocation if co-located). Enable nested triggers, CLR integration, Service Broker, and set the database to TRUSTWORTHY. For secondary sites, is acceptable and can be installed automatically by ConfigMgr. The ODBC driver for SQL Server must also be present as a prerequisite. WSUS configuration is required for software updates integration and must precede the software update point role installation. Supported WSUS versions include those on (with appropriate CUs, as of 2025), (10.0.20348 with 2023-02 CU or later), (10.0.17763 for ConfigMgr 1810+), and (10.0.14393). Install WSUS via Server Manager on the site system , selecting the role with the or a full SQL instance. Do not configure WSUS using its console; instead, ConfigMgr handles and settings post-installation. Ensure IIS is installed on the hosting the software update point, and install the WSUS console on the site if the update point is remote. The site installation occurs through the ConfigMgr Setup Wizard, launched by running setup.exe from the SMSSETUP\BIN\X64 folder on the target server. For a site (CAS) or primary site, the wizard begins with the Getting Started page to select the site type—new for CAS or stand-alone/child for primary—and optionally a typical for simplified setup. Subsequent pages include entering the (evaluation or licensed), accepting license terms, downloading prerequisites, and selecting languages for server and client consoles. On the and Installation Settings page, specify a unique three-character site code, descriptive site name, and installation path. The Site Installation page confirms details, such as joining an existing CAS via FQDN. Database creation is configured during the Database Information page, where the SQL Server FQDN (and port if non-default), instance name, database name (default: CM_<SiteCode>), and Service Broker port (default: 4022) are specified. Customize data and log file paths if needed, ensuring sufficient disk space. The SMS Provider Settings page designates the server hosting the provider (default: site server FQDN). For primary sites, the Client Communication Settings page configures or Enhanced HTTP, followed by the Site System Roles page to install initial roles like management point and distribution point, specifying their FQDNs and communication protocols. The wizard concludes with a settings summary, prerequisite checks (resolving any failures), and the installation progress, where the site database is created and roles assigned in the background. The Configuration Manager console can be installed separately on administrative workstations for remote management. Prerequisites include Microsoft .NET Framework 4.8 (required since version 2403). Run ConsoleSetup.exe from the site server's \Tools\ConsoleSetup folder or the installation media's \SMSSETUP\BIN\I386 path. In the wizard, enter the site server's FQDN and choose the installation directory, then proceed to install. For silent deployment, use the command line: ConsoleSetup.exe /q TargetDir=<Path> DefaultSiteServerName=<FQDN>. The console connects to the site upon launch, providing read-write access for . Post-installation verification involves testing client push installation and configuring boundaries to ensure proper client discovery and management. Enable client push in the console under Administration > Site Configuration > Sites > Properties > Client Installation Settings, specifying the installation properties and accounts with local admin rights on target devices. Test push installation on a sample client by right-clicking the device in the Assets and Compliance workspace and selecting Install Client, monitoring the CCM.log on the site server for success (e.g., no access denied errors) and the client's ccmsetup.log for completion. Configure boundaries under Administration > Hierarchy Configuration > Boundaries, defining IP subnets, AD sites, or ranges that match your , then assign them to boundary groups for site assignment and content access. Verify boundary functionality by checking client site assignment in the console's device properties and ensuring discovery methods like AD System Discovery populate resources correctly.

Initial Configuration and Best Practices

After completing the installation of Microsoft Configuration Manager (Configuration Manager), initial configuration involves setting up methods to populate the site with client devices and users. System Discovery identifies computer resources by querying specified containers in Domain Services (AD DS). To configure it, navigate to the workspace in the Configuration Manager console, expand Hierarchy Configuration, select Methods, and choose System Discovery. In its properties, specify LDAP paths to AD containers (e.g., LDAP://CN=Computers,DC=contoso,DC=com), enable recursive search of child containers if needed, and assign an discovery account with read permissions. Set a polling schedule, such as full discovery weekly and delta discovery daily, to balance data freshness with network load. Similarly, User Discovery locates user accounts for tasks like targeting; configure it by defining AD container locations, using the same discovery account, and establishing a polling schedule. These methods ensure comprehensive client population without manual intervention, though excluding unnecessary subcontainers (available since version 2203) refines results and reduces overhead. Site maintenance tasks are essential for ongoing reliability post-initial setup. The default Backup Site Server task safeguards the site database and configuration for disaster recovery; Microsoft recommends scheduling it at least every five days to align with SQL Server transaction log retention, adjustable based on environment size and change frequency. Enable and review all predefined tasks via the console under Administration > Site Configuration > Sites > Properties > Maintenance Tasks tab, including Delete Aged Status Messages (to clear old data weekly) and Rebuild Indexes (monthly for database optimization). Log monitoring supports proactive maintenance; examine smsexec.log on the site server daily for component thread processing and errors, as it records all site executive activities. Complement this with sitecomp.log for site component maintenance, sitestat.log for system availability and disk space, and compmon.log for thread status—all located in the site's Logs folder—to detect issues like service failures early. Best practices emphasize security, efficiency, and scalability from the outset. For secure client communication, configure using (PKI) certificates on management points and distribution points if a is available, as it encrypts all system interactions; alternatively, enable enhanced HTTP (self-signed certificates generated by Configuration Manager) for non-PKI environments, which secures key endpoints without additional infrastructure since version 2103, when plain HTTP became deprecated. Access this in properties under the Communication Security tab. Boundary optimization prevents performance bottlenecks by defining network locations (e.g., subnets or AD sites) accurately; create boundaries in the console under > Configuration > , then group them logically in Boundary Groups to associate clients with systems like distribution points—use the fewest boundaries possible, avoid overlaps for assignment, and enable fallback to neighboring groups for content access. For scalability in environments with 10,000+ clients, provision servers with at least 12 CPU cores, 64 GB , and 5,000 SQL on SSD storage (e.g., 10 configuration); limit hardware to weekly cycles with minimal attributes, schedule collection updates off-peak, and test I/O performance using tools like Diskspd to ensure handling of large inventories without . Troubleshooting basics address common post-configuration pitfalls. Site reset restores site components without altering settings, useful after account changes, OS upgrades, or corruption; run it via setup.exe from the Configuration Manager bin folder, selecting "Perform site maintenance or reset this site" and "Reset site with no configuration changes"—this restarts services, recreates shares, and reinstalls components, requiring local admin rights but not supported on secondary sites. For replication issues between sites, monitor incoming/outgoing queues in the console under Monitoring > Database Replication; common causes include stopped SMS Executive service, disk space shortages, or SQL throttling—use the Replication Link Analyzer tool to diagnose connectivity and permissions, or run SPDiagDRS in for detailed error analysis in RCMCtrl.log. Address backlogs by increasing sender threads or removing rate limits if copy processes lag.

Integration and Extensibility

Co-Management with

Co-management enables organizations to manage and later devices simultaneously using Microsoft Configuration Manager and , bridging traditional on-premises infrastructure with cloud-native capabilities for a hybrid management approach. This model supports two primary paths: upgrading existing Configuration Manager clients to hybrid joined devices for automatic Intune enrollment, or provisioning new internet-based devices via Intune with subsequent Configuration Manager client installation. By allowing concurrent management, co-management provides flexibility to retain on-premises control while leveraging cloud efficiencies, without requiring an immediate full migration. A core aspect of co-management is the ability to shift specific workloads from Configuration Manager to Intune, enabling phased adoption of cloud management. Configurable workloads include compliance policies, policies, resource access (such as certificates and profiles), endpoint protection, device configuration, Click-to-Run app management, and client app deployment. Organizations can pilot these shifts on a of devices using dedicated collections before applying them site-wide, ensuring minimal risk during transition. The Management Gateway facilitates this process by enabling Configuration Manager to communicate with and manage internet-connected devices enrolled in Intune, eliminating the need for VPN connections and supporting remote workload execution. To implement co-management, several prerequisites must be met, including licensing for Microsoft Entra ID P1 or P2 and Microsoft Intune, along with a supported version of Configuration Manager's current branch. Devices require hybrid Microsoft Entra ID join status, achieved through Azure AD Connect for synchronization between on-premises Active Directory and Microsoft Entra ID, and automatic enrollment into Intune for Windows 10 version 1803 or later (or Windows 11). Administrative permissions, such as Global Administrator in Microsoft Entra ID and appropriate roles in Configuration Manager, are also essential, as is enabling cloud attach features like tenant attach for device synchronization. Once prerequisites are satisfied, co-management is enabled via the Configuration Manager console's Cloud Attach Configuration Wizard, which automates the integration setup. Key benefits of co-management include seamless integration with Windows Autopilot, which automates device provisioning and out-of-box experience for zero-touch deployment in cloud scenarios. It also supports conditional access policies in , enforcing security requirements based on Intune-reported device compliance, thereby enhancing access control for corporate resources. The phased migration approach allows organizations to test and validate workload shifts incrementally, reducing operational disruption and enabling a tailored path to modern management while maintaining visibility across both tools. Additionally, co-management provides centralized device health monitoring and remote actions like restarts or wipes through Intune, complementing Configuration Manager's on-premises strengths. Management insights in Configuration Manager offer analytical guidance for co-management decisions, assessing environment readiness and recommending workload shifts based on site database analysis to optimize hybrid setups. This includes a for unified reporting on states, progress tracking via weighted indexes, and of critical actions like enabling co-management prerequisites. As of November 2025, these continue to evolve, with the announced transition to an annual release cadence starting with version 2609 in September 2026, emphasizing stability and integration with Intune for ongoing hybrid management improvements.

API and Automation Capabilities

Microsoft Configuration Manager (ConfigMgr) provides several programmatic interfaces that enable administrators and developers to automate tasks, query site data, and extend functionality beyond the graphical console. These capabilities leverage (WMI), , and scripting to support custom integrations and efficient management of large-scale environments. By utilizing these tools, organizations can script deployments, monitor compliance, and integrate with broader workflows, reducing manual intervention in IT operations. The WMI Provider serves as the foundational interface for interacting with ConfigMgr's site database, allowing programmatic access to query and modify objects such as devices, applications, and collections. Developers connect to the SMS Provider—a WMI-based component installed on the site server—using languages like , C#, or to retrieve or update data in real-time. For instance, cmdlets like Get-CMDevice enable retrieval of device inventory details without navigating the console, facilitating automated reporting and decision-making processes. This provider uses the Extended WMI Query Language (WQL) for queries, ensuring compatibility with SQL Server views that store ConfigMgr data. Introduced in version 1810, the AdminService offers a modern RESTful interface based on the (OData) v4, designed for cloud-attached ConfigMgr hierarchies. This exposes endpoints over for read and write operations on site resources, such as creating deployments or managing software updates, and supports authentication via Azure Active Directory or certificates. It is particularly useful in environments, where scripts or applications need to interact with ConfigMgr from remote locations without direct WMI access. Native ConfigMgr features, like the console's scripting capabilities, internally utilize this , and developers can extend it for custom scenarios by querying entities like collections or devices through standard HTTP clients. The SDK, included in the Configuration Manager console, provides approximately 600 cmdlets within the ConfigurationManager module for comprehensive . Administrators can import the module to script tasks like application deployments, compliance checks, or site maintenance directly from sessions. This SDK builds on the WMI Provider, translating cmdlets into underlying queries, and supports integration with for hybrid runbooks that orchestrate ConfigMgr actions across on-premises and cloud resources. For example, runbooks can invoke cmdlets to trigger client policy refreshes or collect inventory data, enabling scheduled in without on-site agents. Extensibility is further enhanced through custom reporting and event-driven mechanisms. Using SQL Server Reporting Services (SSRS), integrated with ConfigMgr, developers can create tailored reports by building report models from the site's database views, allowing users to generate ad-hoc insights on metrics like patch compliance or hardware inventory. These reports can incorporate parameters for dynamic filtering and are accessible via the console or web portal. Additionally, webhook triggers enable external systems to respond to ConfigMgr events, such as deployment completions, by configuring notifications that POST data to custom endpoints for integration with tools like Azure Logic Apps.

Third-Party and Cloud Integrations

Microsoft Configuration Manager (ConfigMgr) integrates with (formerly Azure Active Directory) to enable secure authentication for cloud-based features, such as the Cloud Management Gateway (CMG), allowing devices to communicate with on-premises infrastructure without a VPN. This integration supports automatic client registration and certificate-based authentication for hybrid environments, enhancing security for remote management scenarios. For content distribution, ConfigMgr leverages Storage to create cloud-based distribution points (CDPs), which serve as off-site repositories for software packages and updates, reducing bandwidth demands on on-premises servers. These CDPs use virtual machines as front-ends to Azure Blob Storage, enabling scalable content delivery to internet-connected clients while maintaining compatibility with existing site systems. ConfigMgr supports third-party integrations for (ITSM) through connectors like the ServiceNow Microsoft Endpoint Configuration Manager Spoke, which automates tasks such as managing device collections, deploying applications, and querying compliance status directly from workflows. Additionally, the Service Graph Connector imports ConfigMgr asset data into 's Configuration Management Database (CMDB), facilitating unified incident tracking and asset reconciliation in hybrid IT environments. For virtualization inventory, ConfigMgr integrates with environments via System Center Virtual Machine Manager (VMM), allowing discovery and management of VMware hosts and virtual machines as part of the overall endpoint inventory process. This enables administrators to collect hardware and software details from VMware-based assets, including VM configurations and resource utilization, through VMM's direct connection to vCenter Server. To extend management to non-Windows platforms, ConfigMgr employs the native macOS client, a 64-bit package that supports , collection, and reporting on Apple devices running macOS. For Linux systems, where native client support ended with 1902, third-party agents and connectors—such as those from or —provide extender solutions for , patching, and configuration enforcement, often via ConfigMgr's for custom integrations. As of November 2025, ConfigMgr supports integrations with cloud providers like AWS and Google Cloud through third-party tools and APIs for multi-cloud management, such as using AWS Systems Manager for patching in AWS environments and OS Config in Google Cloud, often in conjunction with open-source automation like .

Branding and Naming

Historical Name Changes

Microsoft Configuration Manager traces its origins to Systems Management Server (SMS), introduced by Microsoft in 1994 as SMS 1.0, a tool designed for managing large-scale networks of Windows-based systems. Subsequent versions, including SMS 1.2 in 1996, SMS 2.0 in 1999, and SMS 2003 released in 2003, retained the SMS branding through 2006, focusing on , inventory, and capabilities across environments. This period marked the product's evolution from basic server management to comprehensive systems administration, with SMS 2003 supporting and enhancing patch management features. In 2007, rebranded the product as System Center Configuration Manager (SCCM) with the release of version 2007, integrating it into the broader System Center suite to emphasize its role in unified IT management across desktops, servers, and datacenters. The name change addressed confusion with the original acronym, which overlapped with Short Message Service, and aligned the tool with Microsoft's Dynamic Systems Initiative for modular systems management. SCCM remained the official name through 2018, encompassing versions such as 2012 and the shift to a current branch model in 2016, which introduced more frequent updates and cloud integrations. From December 2019, with version 1910, Microsoft renamed the product to Microsoft Endpoint Configuration Manager (MECM) to highlight its expanding focus on endpoint devices amid the rise of hybrid environments and mobile management. This rebranding positioned MECM as a core component of the Microsoft Endpoint Manager suite, alongside , facilitating co-management of on-premises and cloud-based endpoints. The name persisted through versions up to 2203 in 2022, reflecting adaptations like enhanced support for modern device compliance and security. In April 2023, with version 2303, simplified the branding to Microsoft Configuration Manager, removing the "Endpoint" descriptor to broaden its appeal in scenarios while maintaining continuity with prior capabilities. This change underscored the product's maturation into a versatile platform for device lifecycle management, without altering its core functionality or integration pathways.

Current Product Positioning

Microsoft Configuration Manager serves as the on-premises and hybrid core within the suite, enabling organizations to manage devices across diverse environments without requiring a full migration from existing infrastructure. It integrates seamlessly with for co-management, allowing simultaneous oversight of Windows devices using both on-premises controls and cloud-based capabilities, thus supporting a strategy. This positioning emphasizes its role in bridging traditional IT setups with modern cloud services, particularly for scenarios involving complex , patch management, and compliance enforcement that demand granular, site-based control. The primary target audience for Configuration Manager comprises large enterprises requiring advanced on-premises management alongside cloud integration, such as those handling extensive server fleets, desktop deployments, and mobile device platforms in regulated industries. These organizations benefit from its ability to maximize hardware and software investments while enhancing IT productivity and user empowerment through features like endpoint protection and inventory tracking. Unlike purely cloud-native tools, it caters to environments where , , or legacy system dependencies necessitate hybrid approaches. Licensing for Configuration Manager is included in E3 and E5 plans, as well as Enterprise Mobility + Security (EMS) E3 and E5 subscriptions, providing access to the current branch version without additional cost for eligible users. For standalone deployment, it is available through programs, requiring Software Assurance (SA) or equivalent subscriptions to maintain current branch rights; perpetual licenses support the Long-Term Servicing Branch (LTSB) post-SA expiration. Co-management scenarios further leverage Intune licensing for non-Windows devices, ensuring comprehensive coverage. Looking ahead, has announced a transition to an annual release cadence for Configuration Manager starting with version 2609 in fall 2026, focusing on security, stability, and essential updates to sustain long-term viability in setups. This direction aligns with broader endpoint strategies, with Intune driving primary innovations while Configuration Manager's evolution prioritizes interoperability to support these advancements in enterprise-scale deployments.

References

  1. [1]
    What is Configuration Manager? - Microsoft Learn
    Jun 19, 2024 · Learn the basics of Microsoft Configuration Manager.Introduction · User Interfaces · The Configuration Manager...
  2. [2]
    Microsoft Configuration Manager Current Branch
    Microsoft Configuration Manager helps IT manage PCs and servers, keeping software up-to-date, setting configuration and security policies, and monitoring ...
  3. [3]
    Get started with Configuration Manager programming - Microsoft Learn
    Oct 9, 2022 · You should recognize that Configuration Manager, previously Systems Management Server (SMS), has quite a long history as a product. In ...Architectural Understanding · Namespaces And Classes · Basic Tools<|control11|><|separator|>
  4. [4]
    ConfigMgr at 25 | Microsoft 365 Blog
    Sep 26, 2017 · In 2007, we changed the name from “SMS” to “ConfigMgr,” in order to align it with the System Center brand. Desired State Configuration (DSC) ...How It All Began · Pushing The Architecture... · What's Next
  5. [5]
    Updates and servicing - Configuration Manager - Microsoft Learn
    For example, on the Visual Studio Subscriptions Portal, search for Microsoft Configuration Manager . Note. * Supported Versions in Configuration Manager: In ...
  6. [6]
    Microsoft Configuration Manager - Microsoft Lifecycle
    Starting with version 2303, Microsoft Endpoint Configuration Manager has been rebranded as Microsoft Configuration Manager.
  7. [7]
    Microsoft Defender for Endpoint - Configuration Manager
    Dec 16, 2024 · Download the Microsoft Configuration Manager onboarding package from the Microsoft Defender for Endpoint portal. Update the existing Microsoft ...
  8. [8]
  9. [9]
    MICROSOFT's SYSTEM MANAGEMENT SERVER 1.0 FOR ...
    Oct 25, 1994 · MICROSOFT's SYSTEM MANAGEMENT SERVER 1.0 FOR WINDOWS 3.5 LAUNCHED WITH 25 THIRD PARTY BACKERS. CBR Staff Writer October 25, 1994. Share this ...Missing: history | Show results with:history
  10. [10]
    Microsoft System Center Configuration Manager 2007
    Releases ; Service Pack 2, 2009-10-22T00:00:00.000-08:00, 2019-07-09T22:59:59.999-08:00 ; Service Pack 1, 2008-05-21T00:00:00.000-08:00, 2011-01-11T22:59:59.999- ...Missing: history | Show results with:history
  11. [11]
    Chapter 3: Looking Inside Configuration Manager - Network World
    Jul 30, 2009 · Active Directory Integration—Configuration Manager 2007's integration with Active Directory provides authentication and access control. The ...
  12. [12]
    App-V and SCCM 2007 R2: Are Virtualised Applications Delivered ...
    Sep 11, 2008 · Just like the existing Virtual Application/Management Server in App-V, SCCM 2007 R2 supports application versions, so that you can upgrade and ...
  13. [13]
    Q. Can I virtualize Microsoft System Center Configuration Manager ...
    A. Virtualized environments support SCCM 2007 depending on the service pack level of SCCM. SCCM 2007 RTM is supported under Virtual Server 2005 R2 but not ...
  14. [14]
    Changes from version 2012 - Configuration Manager - Microsoft Learn
    Feb 21, 2023 · The December 2015 release (version 1511) of Configuration Manager was the initial release of the current Configuration Manager product from ...
  15. [15]
  16. [16]
  17. [17]
    Licensing and branches - Configuration Manager | Microsoft Learn
    Oct 3, 2022 · The current branch requires an active Software Assurance agreement or equivalent rights to Configuration Manager. For more information, see ...
  18. [18]
    What's new in Configuration Manager incremental versions
    Mar 31, 2025 · Later updates have version names like 2107, which indicates an update that was created in July 2021.
  19. [19]
    Step-by-Step SCCM 1910 Upgrade Guide - System Center Dudes
    Nov 29, 2019 · Microsoft has released a third SCCM version for 2019. This is the first version of the new Microsoft Endpoint Configuration Manager Branding!
  20. [20]
    Co-management for Windows devices - Microsoft Learn
    Dec 4, 2024 · Co-management enables you to concurrently manage Windows 10 or later devices by using both Configuration Manager and Microsoft Intune.Benefits · Prerequisites · Microsoft Entra Id
  21. [21]
    Support for Windows 11 - Configuration Manager - Microsoft Learn
    Jul 31, 2025 · Starting in version 2403 OS deployment is supported for All Windows 11 (ARM64), you can deploy a task sequence with a feature update to a ...
  22. [22]
    Bulk deploy the Microsoft Teams desktop client
    Sep 10, 2025 · In this article​​ Microsoft provides an executable (.exe) file for the Teams client. This executable allows you to deploy the application ...Uninstall the Teams client · Common HRESULT Values<|separator|>
  23. [23]
    What's new in Microsoft Purview
    Device Onboarding. Fully updated: Onboard Windows 10 and Windows 11 devices using Microsoft Configuration Manager ... Last updated on 2025-10-28. In this ...
  24. [24]
    What's new in version 2403 - Configuration Manager - Microsoft Learn
    May 2, 2024 · Starting Configuration Manager version 2403, Microsoft Azure Active Directory is renamed to Microsoft Entra ID within Configuration Manager. For ...
  25. [25]
    Fundamentals of sites and hierarchies - Configuration Manager
    Oct 3, 2022 · Configuration Manager uses a hierarchy of sites, starting with a central or stand-alone primary site, then child primary and secondary sites. ...
  26. [26]
    Plan the site database - Configuration Manager - Microsoft Learn
    Oct 3, 2022 · SQL Server is used to store information for Configuration Manager sites. Each site in a Configuration Manager hierarchy contains a site database ...
  27. [27]
    Install a secondary site - Configuration Manager - Microsoft Learn
    Oct 3, 2022 · Before you start the secondary site installation, make sure that your user account has the prerequisite permissions. Also make sure that the ...
  28. [28]
    Manage distribution points - Configuration Manager - Microsoft Learn
    Jul 17, 2025 · In the Configuration Manager console, go to the Administration workspace, and select the Distribution Points node. Select one or more ...Install a distribution point · Distribution point · Drive Settings · Pull Distribution Point
  29. [29]
    Plan site system roles - Configuration Manager - Microsoft Learn
    Oct 3, 2022 · Each Configuration Manager site you install includes a site server that's a site system server. The site can also include additional site system servers on ...
  30. [30]
    Understand components and threads - Configuration Manager
    Feb 11, 2025 · This article helps you understand components and threads for content distribution. Original product version: Configuration Manager current ...The Components Used For... · Choosing The Right Values · Sender Thread Configuration
  31. [31]
  32. [32]
    Find site resources - Configuration Manager - Microsoft Learn
    Oct 3, 2022 · The management point. Other site system servers that the client can communicate with, like distribution points and software update points.
  33. [33]
    About Configuration Manager Inventory | Microsoft Learn
    Oct 9, 2022 · When it's enabled, the Configuration Manager hardware inventory client agent automatically collects detailed information about the hardware ...About Collecting Hardware... · About Collecting Software...
  34. [34]
    Set up enrollment for on-premises MDM - Configuration Manager
    Oct 3, 2022 · To set up device enrollment, create an enrollment profile, enable user enrollment in client settings, and install the trusted root certificate ...
  35. [35]
  36. [36]
  37. [37]
  38. [38]
    Deploy applications - Configuration Manager | Microsoft Learn
    Dec 16, 2024 · Deploy applications with Configuration Manager · Start the deployment wizard · General information · Content options · Deployment settings.
  39. [39]
    Software Distribution Programs - Configuration Manager
    Oct 3, 2022 · Learn all about software distribution programs and how they are packaged and made available to a collection of clients.
  40. [40]
    Introduction to software updates - Configuration Manager
    Oct 4, 2022 · Software updates in Configuration Manager provides a set of tools and resources that can help manage the complex task of tracking and applying software updates ...Software Updates... · Synchronization On The... · Automatic Deployment Of...Missing: SUP documentation
  41. [41]
    Install and configure a software update point - Microsoft Learn
    Oct 3, 2022 · The software update point is required on the central administration site and on the primary sites to enable software updates compliance assessment.Wsus Settings · Synchronization Source · Maximum Run TimeMissing: ADR | Show results with:ADR
  42. [42]
    Automatically deploy software updates - Configuration Manager
    Oct 3, 2022 · Automatically approve and deploy software updates by using an ADR. The rule can add software updates to a new software update group each time the rule runs.Create An Automatic... · Process To Create An Adr · Script To Apply Deployment...Missing: SUP | Show results with:SUP
  43. [43]
    Manage task sequences - Configuration Manager - Microsoft Learn
    Oct 3, 2022 · Task sequences are located in the Configuration Manager console. In the Software Library workspace, expand Operating Systems, and select Task Sequences.Missing: MDT | Show results with:MDT
  44. [44]
    Create a task sequence with Configuration Manager and MDT
    Oct 26, 2022 · In this article, you'll learn how to create a Configuration Manager task sequence with Microsoft Deployment Toolkit (MDT) integration using the MDT wizard.
  45. [45]
    Optimize Windows update delivery - Configuration Manager
    Feb 11, 2025 · Delivery Optimization is the main download technology and peer-to-peer distribution method built into Windows 10 and later. Windows clients can ...Peer-To-Peer Content... · Peer Cache Comparison Chart · Frequently Asked Questions
  46. [46]
  47. [47]
    Get started with compliance settings - Configuration Manager
    Oct 3, 2022 · Compliance settings let you manage the configuration and compliance of clients in your organization.How compliance settings work · What devices are supported?
  48. [48]
    About Configuration Baselines and Items - Microsoft Learn
    Oct 3, 2022 · Configuration baselines in Configuration Manager contain a defined set of desired configurations that are evaluated for compliance as a group.
  49. [49]
    Plan for and configure compliance settings - Configuration Manager
    Oct 3, 2022 · This procedure configures the default client settings for compliance settings and applies to all computers in your hierarchy.
  50. [50]
    Monitor compliance settings - Configuration Manager - Microsoft Learn
    Oct 4, 2022 · In the Configuration Manager console, click Assets and Compliance > Compliance Settings > Configuration Baselines. In the Configuration ...
  51. [51]
    Endpoint Protection - Configuration Manager | Microsoft Learn
    Oct 3, 2022 · Endpoint Protection in Configuration Manager allows you to create antimalware policies that contain settings for Endpoint Protection client ...Manage malware · Manage Windows Defender...
  52. [52]
    Configure Endpoint Protection - Microsoft Learn
    Learn how to set up Configuration Manager to update and distribute malware definitions for Windows Defender.
  53. [53]
    Fundamentals of role-based administration for Configuration Manager
    Oct 3, 2022 · The role-based administration model centrally defines and manages hierarchy-wide security access. This model is for all sites and site settings.
  54. [54]
    Configure role-based administration - Configuration Manager
    Jul 17, 2025 · In Configuration Manager, role-based administration combines security roles, security scopes, and assigned collections to define the administrative scope for ...
  55. [55]
  56. [56]
  57. [57]
    None
    Nothing is retrieved...<|separator|>
  58. [58]
  59. [59]
    Troubleshoot database replication service issues - Configuration ...
    Feb 11, 2025 · This guide helps administrators diagnose and resolve database replication service (DRS) problems in Configuration Manager.
  60. [60]
    Enable co-management - Configuration Manager | Microsoft Learn
    May 25, 2023 · This option allows you to enable co-management on a subset of clients to initially test co-management and then roll out co-management by using ...
  61. [61]
  62. [62]
  63. [63]
    Management insights - Configuration Manager - Microsoft Learn
    Jun 20, 2024 · Management insights in Configuration Manager provide information about the current state of your environment.
  64. [64]
    Configuration Manager SDK documentation - Microsoft Learn
    The Configuration Manager SDK contains documentation and samples for developing applications that access and modify Configuration Manager data.
  65. [65]
    WMI Configuration Manager Provider Fundamentals - Microsoft Learn
    Oct 3, 2022 · The SWbemServices object represents an authenticated connection to a SMS Provider, and it is the object that you use to retrieve Configuration Manager objects.SWbemLocator · SWbemServices
  66. [66]
    Configuration Manager API reference - Microsoft Learn
    Oct 3, 2022 · This reference contains detailed information about the Configuration Manager class schema, the Extended WMI Query Language (WQL), ...
  67. [67]
    SMS provider WMI schema reference - Configuration Manager
    Oct 9, 2022 · Configuration Manager uses a SQL Server database to store managed object data. Both SQL Server and WMI can be used to view Configuration Manager managed data.
  68. [68]
    What is the administration service - Configuration Manager
    Nov 7, 2023 · The administration service is a representational state transfer (REST) API based on the Open Data (OData) v4 protocol.
  69. [69]
    How to use the administration service in Configuration Manager
    Oct 3, 2022 · Configuration Manager uses the administration service REST API in several native scenarios. You can also use the administration service for your own custom ...
  70. [70]
    How to set up the admin service - Configuration Manager
    Oct 3, 2022 · Use the steps in this article to set up the administration service on your SMS Provider. Before you start, read the administration service Prerequisites.
  71. [71]
    Configuration Manager PowerShell cmdlets - Microsoft Learn
    Jul 3, 2024 · Configuration Manager cmdlets use PowerShell to manage the hierarchy. Access them via the console or by importing the module in a PowerShell ...PowerShell from the... · Import the Configuration...
  72. [72]
    ConfigurationManager Module - Configuration Manager
    This section contains the help articles for the Configuration Manager cmdlets.
  73. [73]
    Connecting an Azure Automation Account to the Configuration ...
    Feb 22, 2022 · This script will run a REST API call against the Configuration Manager Admin Service. It was create specifically for use in Azure Automation.
  74. [74]
    Create custom reports - Configuration Manager - Microsoft Learn
    Oct 3, 2022 · You can use the following procedures to create a basic report model that users in your site can use to build particular model-based reports based on data.Missing: extensibility webhooks
  75. [75]
    Introduction to reporting - Configuration Manager - Microsoft Learn
    Oct 3, 2022 · Reporting in Configuration Manager provides a set of tools and resources that help you use the advanced reporting capabilities of SQL Server Reporting Services ...Sql Server Reporting... · Configuration Manager... · Report LinksMissing: webhooks | Show results with:webhooks
  76. [76]
    Streamlining Configuration Manager Updates Communication with ...
    Jul 20, 2024 · Updated guide: Integrate Configuration Manager with Teams using Azure Logic Apps. Automate SUG updates post-webhook deprecation.<|separator|>
  77. [77]
    Configure Azure services - Configuration Manager - Microsoft Learn
    Nov 16, 2023 · Connect your Configuration Manager environment with Azure services for cloud management, Microsoft Store for Business, and Log Analytics.Available services · Before you begin
  78. [78]
    Configure Microsoft Entra ID for CMG
    Nov 16, 2023 · In the Configuration Manager console, go to the Administration workspace, expand Cloud Services, and select the Azure Services node. · On the ...
  79. [79]
    Cloud distribution point - Configuration Manager - Microsoft Learn
    Feb 11, 2025 · Plan and design for distributing software content through Microsoft Azure with cloud distribution points in Configuration Manager.Missing: documentation | Show results with:documentation
  80. [80]
    Install cloud distribution points - Configuration Manager
    Feb 10, 2025 · In the Configuration Manager console, go to the Administration workspace, expand Cloud Services, and select the Cloud Distribution Points node.
  81. [81]
    Microsoft Endpoint Configuration Manager Spoke - ServiceNow
    The Microsoft Endpoint Configuration Manager (MECM) spoke automates actions to manage user collections, device collections, devices, and application ...Spoke Subflows · Spoke Actions · Spoke ModuleMissing: extensibility | Show results with:extensibility
  82. [82]
    Service Graph Connector for Microsoft SCCM Landing Page
    Use the Service Graph connector for Microsoft System Center Configuration Manager (SCCM) to pull data from SCCM into your ServiceNow instance.
  83. [83]
    Set up VMware servers in the VMM compute fabric | Microsoft Learn
    Dec 3, 2024 · VMM integrates directly with VMware vCenter Server. Through the VMM console, you can manage the day-to-day operations of VMware vSphere hosts ...
  84. [84]
    Microsoft Endpoint Configuration Manager - macOS Client (64-bit)
    Jul 15, 2024 · The 64-bit macOS client allows you to manage Apple devices running the macOS using Configuration Manager (current branch)
  85. [85]
    The Best SCCM Linux Alternatives for Endpoint Management - Puppet
    Jan 29, 2020 · SCCM Linux alternatives include infrastructure automation and management software like Puppet, Ansible, Chef, Symantec, SolarWinds, and more.
  86. [86]
    Deprecated features - Configuration Manager - Microsoft Learn
    This article lists the features that are deprecated or removed from support for Configuration Manager. Deprecated features will be removed in a future update.
  87. [87]
    Microsoft SCCM admins: Get started with AWS Systems Manager ...
    Jul 24, 2020 · Similar to SCCM, Patch Manager uses an agent for AWS Systems Manager to communicate between managed clients and the AWS Systems Manager service.
  88. [88]
    Integrating SCCM as Patch Source with GCP VM Manager for ...
    Jul 23, 2025 · Hi all, I'm working on a hybrid patch management setup and could use your input on best practices or potential pitfalls.
  89. [89]
    Microsoft's Bob Muglia Announces Great Strides Forward for the ...
    Apr 25, 2006 · MOM V3 will be named System Center Operations Manager 2007, while SMS V4 will become System Center Configuration Manager 2007. When customers ...
  90. [90]
    New Microsoft System Center Offerings Extend Management From ...
    Nov 12, 2007 · Now available to customers are System Center Configuration Manager 2007, System Center Data Protection Manager 2007 and System Center Virtual ...
  91. [91]
    Features and capabilities - Configuration Manager | Microsoft Learn
    Jul 17, 2024 · Co-management · Cloud-attached management · Real-time management · Application management · OS deployment · Software updates · Company resource access.
  92. [92]
    Microsoft Endpoint Manager vs. Intune: What's the Difference?
    Sep 18, 2025 · However, in 2019, Microsoft launched Microsoft Endpoint Manager as a new brand that unified Intune and SCCM (plus additional tools). Today, ...
  93. [93]
    Product and licensing FAQ - Configuration Manager - Microsoft Learn
    This FAQ addresses common licensing questions about Configuration Manager current branch and the long-term servicing branch (LTSB) versions.
  94. [94]
    Secure endpoints with Zero Trust - Microsoft Learn
    Jun 25, 2025 · This guide walks you through the steps required to secure your devices following the principles of a Zero Trust security framework.Endpoint Zero Trust... · 1. Register Endpoints With A... · 2. Limit Access To...
  95. [95]
    Microsoft Configuration Manager switching to yearly releases
    ### Summary of Microsoft Configuration Manager Transition