New domain woes and configuration manager

%3CLINGO-SUB%20id%3D%22lingo-sub-1704244%22%20slang%3D%22en-US%22%3ENew%20domain%20woes%20and%20configuration%20manager%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1704244%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EHi%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EI%20have%20a%20dilemma%20with%20a%20customer%20which%20I%20hoping%20I%20can%20get%20some%20advice%20from%20the%20forum%20here...%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThey%20have%20a%20large%20user%20base%20and%20are%20moving%2Fmigrating%20from%20one%20AD%20domain%20to%20another%20within%20the%20same%20AD%20forest.%20This%20is%20to%20address%20some%20issues%20around%20them%20making%20the%20move%20to%20the%20cloud%20with%20their%20old%20domain%20name.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThey%20use%20MECM%20current%20branch%20but%20have%20had%20issues%20using%20this%20whilst%20migrating%20to%20the%20new%20domain.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThey%20cannot%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20class%3D%22IL_AD%22%3Econnect%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Eto%20a%20device%20in%20the%20new%20domain%20such%20as%20using%20the%20remote%20tools%20%E2%80%9CRemote%20Control%E2%80%9D%20or%20%E2%80%9CRemote%20Assistance%E2%80%9D%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThey%20cannot%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20class%3D%22IL_AD%22%3Edeploy%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3EApp-v%20applications%20through%20MECM%20to%20new%20domain%20user%2Fgroup%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20class%3D%22IL_AD%22%3Ecollection%3C%2FSPAN%3E(s)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20seems%20the%20service%20accounts%20are%20not%20working%20within%20MECM%20Administration%20%26gt%3B%20Hierarchy%20Configuration%20%26gt%3B%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20class%3D%22IL_AD%22%3EActive%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20class%3D%22IL_AD%22%3EDirectory%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3EForest%20%26gt%3B%20Discovery%20%26amp%3B%20Publishing%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELooking%20at%20this%20a%20few%20things%20pop%20into%20my%20mind.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3COL%3E%3CLI%3EMaking%20sure%20appropriate%20client%20push%20and%20network%20accounts%20are%20configured%20for%20new%20domain.%3C%2FLI%3E%3CLI%3EUnderstanding%20how%20the%20AD%20forest%2Fdomain%20trust%2C%20would%20MECM%20need%20two%20way%20trust%3F%3C%2FLI%3E%3CLI%3EWould%20it%20be%20worth%20creating%20a%20new%20MECM%20server%20for%20new%20domain%3F%3C%2FLI%3E%3CLI%3EWould%20a%20CMG%20help%20with%20this%3F%3C%2FLI%3E%3CLI%3EIf%20using%20same%20AD%20could%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%20class%3D%22IL_AD%22%3Eboundary%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Egroups%20and%20AD%20discovery%20help%20with%20separating%20management%20for%20devices%2Fusers%3F%20Would%20AD%20sites%20and%20services%20need%20to%20be%20used%20to%20create%20that%20separation%3F%3C%2FLI%3E%3C%2FOL%3E%3CP%3EI%20was%20thinking%20maybe%20for%20new%20devices%20if%20they%20move%20to%20Intune%20and%20embrace%20new%20devices%20there.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECould%20really%20do%20with%20some%20expert%20guidance%20on%20this%20one%20as%20I%20am%20not%20sure%20what%20would%20be%20the%20best%20approach%20here.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22%20IL_IC_MIN%22%3EMany%20Thanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1704244%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECloud-attached%20management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ECM%20current%20branch%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESite%20Setup%20and%20client%20deployment%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1712671%22%20slang%3D%22en-US%22%3ERe%3A%20New%20domain%20woes%20and%20configuration%20manager%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1712671%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F707989%22%20target%3D%22_blank%22%3E%40isotonic_uk%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3Edid%20you%20check%20the%20side%20boundarys%20%3F%3C%2FP%3E%3CP%3Eany%20kind%20on%20error%20on%20the%20local%20client%20logs%20%3F%3C%2FP%3E%3CP%3Ewhat%20happen%20when%20you%20try%20on%20the%20local%20client%20to%20search%20for%20the%20SCCM%20Side%20(control%20panel)%3C%2FP%3E%3CP%3Eis%20the%20configuration%20inside%20the%20AD%20right%26nbsp%3B%3C%2FP%3E%3CP%3Eany%20kind%20of%20firewall%20between%20the%20Server%20and%20the%20client%20%3F%26nbsp%3B%3C%2FP%3E%3CP%3Ecan%20you%20try%20to%20connect%20from%20the%20server%20to%20the%20Client%20by%20using%20the%20Admin%24%20Share%20%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eklaus%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Hi 

 

I have a dilemma with a customer which I hoping I can get some advice from the forum here...

 

They have a large user base and are moving/migrating from one AD domain to another within the same AD forest. This is to address some issues around them making the move to the cloud with their old domain name.

 

They use MECM current branch but have had issues using this whilst migrating to the new domain.

 

They cannot connect to a device in the new domain such as using the remote tools “Remote Control” or “Remote Assistance”

 

They cannot deploy App-v applications through MECM to new domain user/group collection(s)

 

It seems the service accounts are not working within MECM Administration > Hierarchy Configuration > Active Directory Forest > Discovery & Publishing

 

Looking at this a few things pop into my mind.

 

  1. Making sure appropriate client push and network accounts are configured for new domain.
  2. Understanding how the AD forest/domain trust, would MECM need two way trust?
  3. Would it be worth creating a new MECM server for new domain?
  4. Would a CMG help with this?
  5. If using same AD could boundary groups and AD discovery help with separating management for devices/users? Would AD sites and services need to be used to create that separation?

I was thinking maybe for new devices if they move to Intune and embrace new devices there.

 

Could really do with some expert guidance on this one as I am not sure what would be the best approach here.

 

Many Thanks

2 Replies

@isotonic_uk 

did you check the side boundarys ?

any kind on error on the local client logs ?

what happen when you try on the local client to search for the SCCM Side (control panel)

is the configuration inside the AD right 

any kind of firewall between the Server and the client ? 

can you try to connect from the server to the Client by using the Admin$ Share ?

 

 

klaus 

Thanks Klaus I will take this points on board when performing a review of the customers environment. I will report back.