Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

NEW Managing VPN users modern methods

  • Thread starter Thread starter harveybham
  • Start date Start date
  • Replies Replies 3
  • Views Views 2K

harveybham

Well-Known Member
Messages
86
Solutions
1
Reaction score
5
Points
8
Hi All,
Our company has gone from having multiple offices with multiple DP's to about 80% of the workforce working at home on the VPN. As this is the case managing these clients over the VPN is becoming difficult and we need to look at modern methods. Currently we have patches downloading straight from the internet rather than a DP (the DP has no patches hence why SCCM uses split tunnel for the client). This works great but it all depends if the client is on the VPN.

The other issue is with software updates and new applications, currently we deploy them in batches as they all go via a DP over the VPN, as you can imagine this is using a lot of bandwidth.

What is the best way to manage remote clients and getting them to download content from the cloud rather than a DP over the VPN?

Our SCCM version is currently 1908

I may be answering my own question here but is it a Cloud management gateway (CMG) that i need? from reading about this you can now enable a CMG to also act as a Cloud DP.
Or should i only stick to a Cloud DP?

I ideally would like to both manage clients over the internet (rather than replying on them being on the VPN) and I would also like all content to come from a cloud DP (rather than over the VPN)

We would ideally not tell our users that we can manage them without VPN as we would still like them on the VPN for DC communication but if they do not connect then we would still like to manage them. Currently we do not have anything such as direct access or always on vpn available.

Thank You
 
IMHO, Co-Management with inTune is the way to go. So configure Hybrid-join AD and co-managed your devices. You can then use inTune to push updates. You can define in your SCCM Client Settings of what you still want to use SCCM and inTune for.

CMG as the name suggest is an internet facing management point so your clients dont need VPN to contact MP.

So the big question is what are you trying to achieve? If you still have inhouse app that cant be deployed from intune then you still need SCCM.
 
Hi Edy,

Thanks for the reply. I have looked at Using Intune but currently we are not ready for this yet as we have so many other projects taking place.

I am trying to achieve managing the inhouse catalogue of Apps (250+) via sccm but would like them to get content from a cloud storage and also would like non VPN clients to still be able to communicate back to the Management point. If i go ahead with CMG can i use this as a distribution point as well ?
 
Back
Top