Targeted Certificate Deployment - Only to workstations?
we're preparing our environment brand new sccm installation - there has never been 1 here before. organization not deploy workstation certificates. design issue i'm seeing:
sccm not used manage servers. used manage workstations. need ability deploy workstation certificate all workstations , only workstations. autoenrolling of certificates via gpo seems best option.
servers have gpo enables autoenrollment them already. workstations not.
plan on creating gpo , targeting workstations enable autoenroll of certificates.
when creating certificate template sccm, typically set permissions allow domain computers 'enroll' permission.
if set template 'enroll' permission domain computers, include servers too. servers autoenroll sccm certificate. need avoid that.
there doesn't exist ad group workstations. creating 1 easy, hard manage new systems added domain.
have recommendations how proceed domain workstations receive sccm workstation certificate?
thanks
you can create ad group , add computers there. once done, make template available group have created. can use powershell script automatically populate group members based on criteria operating system.
once done, can apply auto-enrollment gpo on workstations.
this posting provided no warranties or guarantees , , confers no rights.
ahmed malek
Windows Server > Directory Services
Comments
Post a Comment