CMG client troubleshooting
We have cmg configured in our environment, but the problem is many devices are not having cloud policy and those can’t come back to network due to covid 19 situation. Need your advise on how those machine can talk to SCCM? Any registery changes or again SCCM installation with tenant id and cmg detail will work? We don’t have intune and clients are azure AD joined.
Answers ( 10 )
First resort for your troubleshooting is look at CMG and MP logs whether those client requested for tokens and MP provisioned and authorized it.
Second look at those devices Azure AD device registration and the device should be registered (dsregcmd /status) PRT and WAM should be enabled.
If you are open to learn about fiddler.. just investigate Azure AD authentication process through fiddler traces.
Validate Azure MFA of SCCM server app excluded for those devices in Conditional Access policy
All this will give you a hints..
These clients do not have cmg information. Network tab is empty. Mostly belong to one of our primary site where connection point was installed later and many devices went outside already by that time.
Did you get any resolution with this issue?
No Anoop, we have manually added reg for cmg but its working for some clients, not for all. still facing issues.
Any update here?
Anything related in these two threads
What version of ConfigMgr are you uisng? Is TLS 1.2 enforced for you CMG?. Can these clients resolve your CMG destination?
We have 1910. Those clients do not have CMG information. Network tab is empty.
There is no connection issue. It’s working Fine for other clients.
Problem is with only those clients which do not have cmg policy. How can we make those client to talk to sccm.
Hello – Have you tried looking into the following step for client troubleshooting
Fix SCCM Client CMG Communication Failure Error 0x87d0027e | ConfigMgr by Rajul – https://www.anoopcnair.com/sccm-client-cmg-communication-failure/
And Also try CMG server side troubleshooting –
SCCM CMG Troubleshooting Tips with Connection Analyzer – https://www.anoopcnair.com/sccm-cmg-troubleshooting/
Hello Vivek, SCCM CMG connection analyzer tool helps you to analyze end to end CMG communication.
Please check – https://www.anoopcnair.com/sccm-cmg-troubleshooting/