SCCM WDS PXE Boot Authentication

Hi All,

The ability to do domain authentication for a PXE boot in RIS could be achieved by modifying the security directly on the image folder on the RIS server - however, I can't seem to implement the same access control in SCCM 2007 SP1 using WDS.

I have set up the capability to build bare metal machines using the OS Deployment feature in SCCM. The image process is advertised to “All Unknown Computers” and starts with the “builder” hitting F12 on the workstation. The boot image is loaded from the DP share and then the process begins.

My question is: How can I protect the PXE boot process by having the system request a domain Username and Password in order to begin the PXE boot process and also limit who can see the advertisements for the avialable images.

Thanks,

phil

  • Moved by Torsten [MVP]MVP Monday, March 29, 2010 7:36 PM moved to OSD subforum (From:Configuration Manager Setup/Deployment)
March 29th, 2010 10:26pm

Hi,

Thanks for the reply.

Yes - I did in fact set the password properties in the PXE boot service role on the SCCM server. However, that means I have to give that password out to everyone that needs to build a machine. This makes it difficult to control who has the password and does not provide enough security as to who can build machines.

I would really like to use domain authentication (similar to what was availble in RIS) so the "builder" has to enter his domain credentials before being enable to continue with the build process. This way only those people identified in AD would be able to build machines.

Any other suggestions would be appreciated.

Thanks,

Phil

 

March 29th, 2010 11:57pm

I think there's no such feature built-in to grant rights based on domain authentication. However, I suppose it is possible to create a HTA script that is run as the first task of task sequence and which can decide, based on credentials, whether or not to proceed with task sequence.
Free Windows Admin Tool Kit Click here and download it now
March 30th, 2010 12:25am

Thanks - yep a custom script looks like the way to go. I was hoping there would be some way of stopping the process before it really gets started - at the PXE boot stage, but doesn't look like it.

Thanks for all the imput....appreciated.

Phil

 

March 30th, 2010 6:02pm

some way of stopping the process before it really gets started  

Not exactly what you're looking for but you could have a look at the pre-execution hook: http://technet.microsoft.com/en-us/library/bb694075.aspx
Free Windows Admin Tool Kit Click here and download it now
March 30th, 2010 7:05pm

Did you ever get this working? I'm working obn the same thing. If you could share your solution it would be great. Louis
May 13th, 2010 2:40pm

Hi... did you ever get this working? I'm looking to do exactly the same thing
Free Windows Admin Tool Kit Click here and download it now
July 6th, 2013 1:33pm

Phil Did you ever develop a solution? we are currently implementing SCCM 2012 and i would like to include AD authentication rather than standard password protection. thanks
February 14th, 2014 9:27am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics