Installing new secondary MP, DP & SUP



I have a ConfigMgr 2012 (2002) with Primary site, MP, SUP and 2 DPs.

Work-group clients was manged by my site system until i switch to HTTPS.

now all my Work-group clients are undiscovered and un-managed.

Am planing to deploy another MP, DP and SUP for those with HTTP only.

will this work or there is another suggestion can be done?

Also i have a remote site (another domain) which i need to add them to my site system , can i manage them using the new MP?

Answers ( 5 )


    So if I understood correctly , you are now using CA issues certs … there is no problem for domain joined machines since they receive the certs as part of GPO auto enrollment and the issue is for workgroup machines since they cannot auto enroll these certs.

    I think there is a possibility to issue the certs to workgroup machines as well, you may need to check with your PKI team , they might have specific template to be used for this with certain custom settings.

    Worth to check with PKI team.

    When you say until you switched HTTPS :

    How were these work-group machines managed ? Did you use self signed ConfigMgr certs for agent communication ?

    Now when you switched to HTTPS, hope you are using / configured required PKI certs and that understanding i think you need to use appropriate client authentication certificate on your end points issued by your PKI should address the problem.


      Hi Guru,
      Yes, i used to use self signed Cert, after switching to https, PKI cert been enrolled on all the domain end points, and that’s why i need a solution for my work-group clients as it wont be able to communicate with my CA to get the Cert.


    If you have trust between those domains then you can use the MP in the other domain to manage clients in a different domain.

    If there is no trust, then you might need build a separate MP,DP , SUP on that remote domain to manage clients from there

    Remote DP installation

    New DP –
    New MP –

