Documente Academic
Documente Profesional
Documente Cultură
Pradeep.chandrasekharan@hotmail.com
What can you do with
SMS?
Remotely diagnose / troubleshoot
desktops and servers
Install applications or remotely run
commands
Patch management
Manage existing software
Asset / inventory / resource management
Pradeep.chandrasekharan@hotmail.com
SMS 2003 Capabilities
Security
HW/SW
Patch
Inventory
Management
Application Remote
Deployment Control
Software
Metering
Pradeep.chandrasekharan@hotmail.com
SMS Security Modes
Pradeep.chandrasekharan@hotmail.com
Standard Security Mode
Pradeep.chandrasekharan@hotmail.com
Advanced Security Mode
SMS 2003 advanced security uses the local system account on SMS servers to
run SMS services and make changes on the server. Advanced security uses computer
accounts (rather than user accounts) to connect to other computers and to make
changes on other computers. Computer accounts can be used only by services
running in the local system account context, and only administrators can configure
services. Therefore, advanced security is a very secure mode.
The local system account and computer accounts have several advantages over user
accounts:
The local system account is local to the computer itself so the jurisdiction of the
account is very limited.
Only the operating system knows the password for a computer account so network
users cannot use computer accounts to access network resources.
The local system account does not have a password or require one. Local system and
computer accounts do not require any manual maintenance, even in organizations that
require that all passwords be changed on a regular basis because the computer
regularly and automatically changes computer account passwords.
Domain-level privileges are not required. Privileges are required only on the SMS
servers themselves.
Pradeep.chandrasekharan@hotmail.com
Remote Management in SMS
Remote Reboot utility, administrators can
restart the selected client
Run an application or batch file on a remote Windows
based client
When a user is present at the remote machine (98 or
2000), a remote control session of that client may be
initiated
Remote Assistance feature is used for remotely
troubleshooting XP clients directly from the Systems
Management Server 2003 Administrator Console when
a user is present at the remote machine
Client software is automatically installed on
Windows based computers within the site boundaries
Pradeep.chandrasekharan@hotmail.com
SMS 2003
Architecture Overview
Pradeep.chandrasekharan@hotmail.com
Site Systems Roles
Server Locator Management
Point SMS Site
Point
Database
Site
Server
Distribution
Reporting
Point
Client Point
Access
Point
Pradeep.chandrasekharan@hotmail.com
Site Hierarchies
SQL
Primary Site
(Child and
SQL Parent Site)
SQL
Secondary
Site
(Child Site) Primary or
Secondary Site
(Child Site)
SQL
Pradeep.chandrasekharan@hotmail.com
Advance Client
The Advanced Client is a newly developed SMS client, and is the preferred client type for
all computers running Windows 2000 or later in your organization. The Advanced Client is
especially recommended for mobile and remote computers because its architecture is
optimized for enhanced support for those types of computers.
Advanced Clients use management points to send and receive data from the site server.
To receive configuration and advertised program details, Advanced Clients use policies,
which are sent from management points. The Advanced Client policies are unique to SMS
and are not related to policies associated with Active Directory®.
Advanced Clients cannot be assigned to secondary sites. However, they can use proxy
management points at secondary sites to upload data and to download Advanced Client
policies.
Legacy Client
Although it is recommended that you deploy the Advanced Client on all the computers in
your organization running Windows 2000 or later, there are two reasons for deploying the
Legacy Client.
You must deploy the Legacy Client when the client computer is running Windows 98 or
Windows NT 4.0.
When you upgrade your SMS sites from SMS 2.0 to SMS 2003, the Legacy Client is
automatically installed on SMS 2.0 clients running Windows 2000 or later to assist you
with migrating these clients to Advanced Client. It is strongly recommended that you
upgrade these clients to Advanced Client as soon as possible after you upgrade your
SMS site. Pradeep.chandrasekharan@hotmail.com
Advance Client
Better support for mobile computers and remote computers.
Enhanced security.
Use of Background Intelligent Transfer Service (BITS) to transfer data
such as package source files and inventory data.
The Advanced Client can download the package source files to the local
computer before running an advertised program.
Access to SMS package source files on local distribution points at a site, which the Advanced Client is
temporarily roaming to, without being assigned to that site. This includes access to distribution points at SMS
2.0 secondary sites, whose parent site is an SMS 2003 site.
The site server sends to the Advanced Client data that contains only changes to such items as configurations,
advertisements, or software metering rules. This reduces the amount of data that is transferred on the network.
The Advanced Client is highly scriptable, which allows for the automation of Advanced Client configuration and
operations.
The client agents, such as the Hardware Inventory Client Agent, are installed when the core SMS client
components are installed. This ensures that the Advanced Client always has the client agents. This also
eliminates the need for the extra bandwidth that would be necessary to download the client agents when
enabling a feature.
When downloading the Advanced Client software during installation, the Advanced Client installation programs
continue to run even if the network connection occasionally becomes unavailable.
When deploying Advanced Clients, you can complete the installation of the Advanced Client software without
assigning the client to any site. This allows you to complete the installation of a large number of computers in a
staging area, and then transport the installed computers to their destination in the production environment.
Those computers can then be assigned to a site and become fully deployed SMS clients.
Pradeep.chandrasekharan@hotmail.com
Advanced Client Download
And Execute
Distribution Management
Bangalore Point Point
SMS 2003
Primary Site
Chennai
SMS 2003 Primary Site
Distribution
Point
Local Client
Cache
New
Program
Installed
SMS 2003 Advanced Client
Managed by Bangalore Pradeep.chandrasekharan@hotmail.com
Mobile / Roaming / Remote Users
Pradeep.chandrasekharan@hotmail.com
Discovery Methods
Pradeep.chandrasekharan@hotmail.com
Active Directory Site Boundary
Integration
SMS 2003 allows definition of SMS site
boundaries from Active Directory site names
IP subnets need only be defined in one place
and leveraged by SMS
Mixed IP subnets and Active Directory site
boundaries can be used to define an
SMS site
Supports gradual migration- existing IP-based
subnet boundaries still supported
Pradeep.chandrasekharan@hotmail.com
Active Directory Site Boundary
Integration
Pradeep.chandrasekharan@hotmail.com
Active Directory Discovery
Pradeep.chandrasekharan@hotmail.com
Active Directory Targeting
Pradeep.chandrasekharan@hotmail.com
WMI
WMI-Based Inventory
Allows improved client-side performance
during inventory scans
Provides a richer set of inventory data,
including BIOS and chassis enclosure data
Based on the Common Information
Model standard
Allows information from multiple sources
Pradeep.chandrasekharan@hotmail.com
Inventory Capabilities
Increase scale
100,000+ systems on single primary site
5-7X scale over SMS 2.0
More control over software inventory
Better selection criteria
Wildcards, directories, and environment variables
Highlight different inventory permutations, like *.exe, m*.exe,etc.
Exclude encrypted and compressed volumes (critical for servers)
Ability to just get file properties improving system performance
Better reporting on installed applications
WMI provider to inventory Add/Remove Programs data
Both the UI and Registry Information
Easier to track suite of applications
Enterprise Agreement True-Up report
WMI provider to inventory Windows Installer component status
Reduced inventory traffic
Deltas generated on clients, advanced clients use compressed
XML files Pradeep.chandrasekharan@hotmail.com
Software Metering
Client
Windows Media
MS Word
Internet Explorer
Client
SMS Server
Client
Pradeep.chandrasekharan@hotmail.com
Software Metering
Metering provides application
usage tracking
Enables informed purchasing decisions
Allows you to track concurrent licensing
Reduces complexity in enterprise
Administrators have control
Specify what applications to meter
Multi-site configuration tool allow replication of rules
Summarization tasks reduces data store
Tracks user, machine, time, frequency, usage
Usage data can be blocked from flowing up
hierarchy to reduce traffic
Pradeep.chandrasekharan@hotmail.com
Reporting
Extensible web-based reporting tool
Based on automatically maintained, high performance
SQL Views
Schema based on SMS Provider
Documented and supported,
Improvements from original web version
120 pre-built reports
Dashboard functionality makes it easier to customize reports
Multiple reports in a single view
Integrated security support
Internationalized versions
Exporting Reports
Can export/import report properties into other SMS environments
Pradeep.chandrasekharan@hotmail.com
Reporting
Pradeep.chandrasekharan@hotmail.com
SMS 2003
Advantages
Pradeep.chandrasekharan@hotmail.com
Security
SMS 2003 provides a new Advanced
Security mode
Reduces number of service accounts
Less administrative overhead
Leverages Local System account
Domain Admin rights not required
Advanced client platform is recommended
Uses no accounts unlike legacy client
SMS 2003 provides security rights
delegation
Pradeep.chandrasekharan@hotmail.com
Package Delta Replication
SMS 2003 provides file-level delta
replication.
Only new or modified files are replicated.
Down to appropriate child sites.
Out to assigned distribution points (DPs).
Pradeep.chandrasekharan@hotmail.com
Delta Replication
Distribution
SMS 2003 Central Site Point
Distribution Distribution
Point Point
and devices
Pradeep.chandrasekharan@hotmail.com
SMS – Benefits in
Patch management
Gives administrators control over patch management
Allows staging and testing of updates before installation
Fine-grained control of patch management options
Automates key aspects of the patch management process
Can update a broad range of Microsoft products
(not limited to Windows and Office)
Can also be used to update third-party software and deploy
and install any software update or application
High level of flexibility via use of scripting
Pradeep.chandrasekharan@hotmail.com
SMS – What It Does
1. Setup: Download Security Update
Inventory and Office Inventory Microsoft
Tools; run inventory tool installer Download Center
Pradeep.chandrasekharan@hotmail.com
How to Use SMS
1. Open the SMS Administrator Console
2. Expand the site database
3. Right-click ON Any required collection and select All Tasks > Distribute Software
4. Create a new package and program
5. Browse to the patch to be deployed
6. Configure options for how and when the patch should be deployed on the client
Pradeep.chandrasekharan@hotmail.com
Software Update Services: Update Installation
1. SMS Client—Software Update Advertisement
1. Runs the software updates advertisement generated by the Distribute Software
Updates Wizard.
1. command line: PatchInstall.exe /g:0 /n /z:s /f /c:5 /t:30/m:”PatchAuthorize.xml”.
Pradeep.chandrasekharan@hotmail.com
Exporting Queries
Select Queries node
On the Action menu, click All Tasks, and then
click Export Objects
Export Object Wizard appears
Select the queries to be exported (includes standard
queries)
Specify file name and comment
Creates a MOF file with query contents
Comment
Class (SMS_Query)
Security
Syntax
Pradeep.chandrasekharan@hotmail.com
Importing Queries
Select Queries node (or other nodes)
Automatically adds imported objects to correct node
On the Action menu, click All Tasks, and then
click Import Objects
Import Object Wizard appears
Specify MOF file to import
Displays queries to be imported, and also displays
whether you have the Create security rights that you
need
Displays the comment from the MOF file
New queries are added to the appropriate node
Pradeep.chandrasekharan@hotmail.com
What’s New for Reporting?
Crystal Reports are no longer used
Was resource intensive
Was problematic to configure in certain scenarios
Reports were not easily modified or created
The new solution is SMS Reporting
Integrated version of Web Reporting Tool
Released to Web over a year ago
Great response from customers
Easy for users to access reports on the intranet
Easy to create custom reports
Can create custom dashboards
Pradeep.chandrasekharan@hotmail.com
Report Categories
Advertisement Status (6)
Computers (with a specific file)
Hardware (50)
CD-ROM, Disk, General, Memory, Modem,
Network Adapter, Processor, SCSI, Sound
Card, Video Card
Network (9)
Operating System (9)
SMS Site (17)
Client Information, Discovery and Inventory
Information, General, Server Information
Pradeep.chandrasekharan@hotmail.com
Report Categories (2)
Software (16)
Companies and Products, Files
Software Metering (4)
Status Messages (17)
Status Messages – Audit ( 6)
Users (4)
Video Card (no longer supported) (4)
~150 Total
Pradeep.chandrasekharan@hotmail.com
Using Dashboards
Dashboards allow multiple reports to
be displayed in a single Internet Explorer
window
Great for viewing multiple related reports
simultaneously
Great way to monitor status
By default, no dashboards are included
You create what you feel is required
Very easy to create a dashboard
Supply title
Specify specific report for specific row or column of
dashboard
Pradeep.chandrasekharan@hotmail.com
Logs
1. The SMS 2003 Legacy Client logs record the same information as the SMS 2.0 client. The
Legacy Client log files are located in the %Windir%\MS\SMS\Logs folder on the client
computer.
2. The SMS 2003 Advanced Client uses different log files than the Legacy Client to record
information. The Advanced Client logs are located in one of the following locations:
1. On computers that serve as management points, the Advanced Client logs are located in
the SMS_CCM\Logs folder.
2. On all other computers, the Advanced Client log files are located in the %Windir
%\System32\CCM\Logs folder
CcmExec.log –- Records activities of the client and the SMS Agent Host service.
Execmgr.log – Records advertisements that run.
InventoryAgent.log –- This component creates discovery data records (DDRs)
and hardware and software inventory records.
StatusAgent.log –- Logs status messages that are created by the client
components.
LocationServices.log –- Finds management points and distribution points.
PolicyAgent.log –- Requests policies by using the Data Transfer service.
Scheduler.log –- Records schedule tasks for all client operations.
Pradeep.chandrasekharan@hotmail.com
Questions ?
Pradeep.chandrasekharan@hotmail.com