Cross Forest help
Hi
I have been tasked with setting up our current SCCM environment to manage clients in another forest prior to us migrating them into our forest sometime next year. I've checked other posts in the forum and have a good idea of what I need to do but just
wanted to clarify that I am going in the correct direction.
Forest 1 contains our SCCM infrastructure and forest 2 is where the clients are that I need to manage. There will be no SCCM servers in forest 2. Forest 2 trusts forest 1 and SCCM is in mixed mode. I already have an
SLP configured in forest 1 as we manage workgroup computers and I can resolve the SCCM boxes from clients in forest 2.
If I have understood what I have read correctly I can treat the clients in forest 2 in the same way that I would workgroup computers in forest 1 i.e. specify SMSSLP in the installation properties of the SCCM client. My questions are:
1. Is this correct?
2. I'm assuming that the boundaries for clients in forest 2 can be assigned as I would for clients in forest 1?
3. Will I be able to use OSD to deploy OS to clients in forest 2?
4. Is there anything that I have missed? Do I need to give the SCCM computer accounts any access is forest 2?
Thanks in advance.
November 5th, 2010 12:31pm
Hi SRR1012,
1) Well, sort of.
2) Depends on how you assign boundaries in forest 1. For instance, you can use subnets as boundaries.
3) Yes
4) No, you do not need to give the SCCM computer accounts any access in forest 2.
5) SCCM is not limited to Active Directory. This is in fact a key issue. For the SCCM system to work you do not need any trusts. SCCM can manage computers in domains that are not trusted. You just have to specify a network access account. Think of clients
in other domains as clients in a workgroup.Kind regards Tim Nilimaa IT Consultant at Mindgrape (Sweden) Please remember to mark this answer as helpful if it helped you.
Free Windows Admin Tool Kit Click here and download it now
November 5th, 2010 12:59pm
Hi Tim
Thanks for the reply. I probably should have specified that the boundaries would be subnets. Network access account is already there so should be good to go. Thanks for the clarification.
November 5th, 2010 5:23pm
Hi,
For SCCM in multiple AD forest, this article will be helpful:
Configuration Manager in Multiple Active Directory Forests
http://technet.microsoft.com/en-us/library/bb694003.aspxPlease remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
November 9th, 2010 4:31am