Archive

Archive for the ‘v.Next’ Category

v.Next Virtual labs Released

October 6, 2010 1 comment

What’s cool and new in v.Next

Note :- I would prefer to first go through this System Center Configuration Manager v.Next Overview webcast before going through this Blog.

What’s cool and new in v.Next?

While browsing through the v.Next console I have found some interesting and cool features, First thing which impressed me is faster and better console than ConfigMgr 2007,

Console is with the new icon

image

clip_image002

Console is divided in to four panes, you will able to see at the Left bottom of the console

1) Administration

2) Software Library

3) Monitoring

4) Asset and Compliance

clip_image003

Navigation is available at the bottom left, you can move up and down the display button.

clip_image004

Faster navigation from one pane to another pane

image

Quick help when you click on any option in any pane. (I just love this feature)

image

Whole console look changed, new options has been added

clip_image001clip_image002[11]

clip_image003[5]clip_image004[5]

Some new features available with v.Next are…

Distribution point Group -  You can create the Device collections  and user collections and you can link the distribution point group with that collection and then target the packages.

Migration is the feature available with v.Next. here you can manage the migration of data from Configuration Manager 2007 sites to Configuration Manager v.Next sites.

image

RBACRole Based Administration Console for more details please go through RBAC and security in v.Next ConfigMgr

Alerts – You can create the alerts however you can not mail it.

Database replication – Site to site communication is now based on SQL replication

Client health -  You can view client health from the console itself.

Filters – Filter tab is available in each features with filter criteria

image

Reports available based on SQL reporting services.

There are many more new feature and things are in v.Next .We will see in my upcoming blogs.

Thanks and Regards |Abhishek Joshi

RBAC and security in v.Next ConfigMgr

August 24, 2010 1 comment

 

What is RBAC?

RBAC is role based Role Based Administration Console. After implementing this feature you will able to secure objects from other Administrator.

How many Built-in Security Roles are in v.Next?

13

What are they?

clip_image001 

What is the use of each role?

ConfigMgr Administration role

Allows administrative users to have Full Control access to all securable objects in Configuration Manager including security settings, with the exception of permission settings for reporting. Security for reporting is assigned by using SQL Reporting Services security.

clip_image003

clip_image004

clip_image006

Read-only role

Allows administrative users to read all object types in Configuration Manager, except for reporting. Security for reporting is assigned by using SQL Reporting Services security.

Remote Tools role

Allows administrative users to run remote administration tools to help users resolve computer issues. Administrative users that are associated with this role can run remote control, remote assistance, and remote desktop tools from the Configuration Manager console.

Asset Management role

Allows administrative users to configure the Asset Intelligence Synchronization Point site system role, Asset Intelligence reporting classes, software inventory, hardware inventory, and metering settings. Administrative users that are associated with this role can analyze collected client data.

Asset Analyst role

Allows administrative users to view data that is collected through asset intelligence, software inventory, hardware inventory, and metering. Administrative users that are associated with this role can create metering rules and Asset Intelligence categories, families, and labels.

Compliance Settings Management role

Allows administrative users to define, monitor, and remediate noncompliance by using compliance settings and configuration baselines. Administrative users that are associated with this role can create, modify, and delete configuration items and configuration baselines. They can also assign configuration baselines to collections, initiate compliance evaluation, and initiate remediation for noncompliant computers.

Application Deployment role

Allows administrative users to deploy applications. Administrative users that are associated with this role can view a list of applications, and they can manage deployments for applications, alerts, templates and Configuration Manager 2007 advertisements. In addition, administrative users can view collections, status messages, queries, and global conditions.

Application Editor role

Allows administrative users to create, modify, and retire applications. Administrative users that are associated with this role can manage Configuration Manager 2007 packages, and they can read the alerts and status messages for applications.

Application Administrator role

Allows administrative users to perform both the Application Deployment role and the Application Editor role. In addition, administrative users that are associated with this role can manage queries, read and modify site permissions, and manage collections and user device affinity settings.

Operating System Deployment Management role

Allows administrative users to create operating system images and then deploy them to computers. Administrative users associated with this role can manage operating system installation packages and images, task sequences, device drivers, boot images, and state migration settings.

Hierarchy Administrator

Hierarchy Administrator

Software Updates Management role

Allows administrative users to deploy software updates. Administrative users that are associated with this role can run software updates synchronization, download and deploy software updates, and create software update groups, automatic grouping rules, and software update templates. Administrative users can also manage Network Access Protection (NAP) policies.

Mobile Device Analyst role

Allows administrators to add new mobile devices to the system. Administrators associated with this role can use the Create Mobile Device wizard to add new mobile devices to the system and associate them with users. Once the new records are created they can reset the enrollment password on the newly created records.

Which are the related Views in database?

Filter Views by vRBAC

Which are the related Tables in database? 

Filter Tables by RBAC

clip_image008

How many Built-in security scope are in v.Next?

 

1) All

A built-in security scope that contains all securable objects. A Configuration Manager administrator associated with the All security scope will have the permissions of their role for every object in the Configuration Manager environment. This security scope cannot be changed or deleted.

2) Default

A built-in security scope with which securable objects can be associated. This security scope cannot be changed or deleted.

Note :- We can create a new security scope. Alt click Security scope –> create Security

Scope

How to Navigate?

 

clip_image010

 

Can we create custom security roles?

 

Yes with the “copy security role” option.

 

clip_image011 

clip_image012 

 

Can we add /remove security roles for an Account ?

 

Yes.

Go to \Administration\Overview\Security and Permissions\Administrative Users –> Alt click any Account –> Properties

 

clip_image013

Are there any reports available for RBAC?

Yes

image

 

 

Thanks and Regards |Abhishek Joshi

Incoming search terms:

VHD Test Drive – System Center Configuration Manager v.Next on Windows Server 2008 R2

Overview

Download this fully configured virtual machine of the latest release of System Center Configuration Manager v.Next Beta 1. For more information on System Center Configuration Manager R2, please visit the product homepage and the Configuration Manager Techcenter.

Download

Thanks and Regards |Abhishek Joshi

Configuration Manager v.Next Beta 1 now on VHD Test Drive Program

From Jeff Wettlaufer’s blog

Microsoft has released a fully configured virtual machine for ConfigMgr v.Next Beta 1.  Based on a Windows Server 2008 R2 x64 OS, this is a fully built virtual machine ready to import into your Hyper-V environments.

This is something the ConfigMgr team has done for a few major releases, starting back at the ConfigMgr 2007 RTM timeframes.  Microsoft is really excited to get you guys this type of access, to help you evaluate the latest and greatest ConfigMgr v.Next release.  Microsoft is also in the process of uploading the hands on labs for ConfigMgr v.Next as well, look for that announcement soon.

Some resources for you:

  • VHD Test Drive – System Center Configuration Manager v.Next on Windows Server 2008 R2 – link
  • VHD Test Drive – System Center Configuration Manager 2007 R2  – link
  • Configuration Manager vNext Beta 1 evaluation download – link

Thanks and Regards |Abhishek Joshi