SCCM CMG Setup Guide – Part 5 | Setup Cloud Management Gateway

The cloud management gateway (CMG) provides a simple way to manage Configuration Manager client over internet.

In the previous posts we discussed about CMG prerequisites, server authentication certificate requirement for CMG, client authentication certificate reqiurment, SSL configuration for ConfigMgr site and ConfigMgr site integration with Azure Active Directory.

In this post, we will discuss about creating Cloud Management Gateway, adding CMG connection point site system role, configuring other CMG and client related settings.

Post in this series:

Create Cloud Management Gateway

Go to Configuration Manager console Administration/Features and ensure Cloud management gateway with Azure VM scale set is turned on.

Enable Cloud Management Gateway with Azure VM Scale Set

Go to the Administration > Cloud Services > Cloud Management Gateway, right click on Cloud Management Gateway and select Create Cloud Management Gateway

Create Cloud Management Gateway

Sign-in with Azure Administrator rights. The Azure AD App name should be auto-populated, click Next

Setup Cloud Management Gateway

On the Specify additional details for this cloud services page

Specify a server PKI certificate for the cloud service:

  • Certificate file : Click on Browse and select the server authentication certificate you exported for CMG.
  • Service name will populate automatically based on CNAME/Alternative DNS name provided in certificate.
  • Select correct region
  • Validate deployment name (serviceprefix.region.cloudapp.azure.com)
  • Resource Group: Create new one
  • VM Instances: 1

Specify security settings for authenticating client connections through Cloud Management Gateway:

  • Click on the certificate and Upload PKI trusted root certificate you have exported earlier. Refer Export Trusted Root Certificate
  • Select Verify client certificate revocation

Select “Allow CMG to function as a cloud distribution point and serve content from Azure storage

Click on Next

Specify additional details for this cloud service

In the Alert page, leave the default settings and click on Next.

Review the details in Summary page and click on Next to complete the tasks.

Cloud Management Gateway Wizard Summary

In Completion page, click on Close.

Cloud Management Gateway Wizard Completion

You can now see the Cloud Management Gateway service name in console. The Status will change to Ready once provisioning completed.

Cloud Management Gateway

Add CMG connection Point Site System Role

Cloud Management Gateway connection point manage all communication between ConfigMgr on premises infrastructure and Cloud Management Gateway service hosted in Microsoft Azure. Follow the below steps to add a Cloud Management Gateway Connection Point site system role.

In the SCCM console, go to Administration > Site Configuration > Servers and Site system roles > select and right click on Site system server > Add site system roles

Add CMG Connection Point

Click on Next twice to got to System Role Section page. Select Cloud Management Gateway Connection Point and click on Next

Add CMG Connection Point

Select Cloud Management Gateway name and Region and click on Next

Add CMG Connection Point

Confirm the settings and click on Next to finish.

Add CMG Connection Point

In the Completion page, click on Close.

Add CMG Connection Point

Go to Cloud Management Gateway and select CMG service Name. Check if Cloud connection point role status is Connected

Add CMG Connection Point

Configure Management Point to Allow CMG Traffic

The Management Point need to be configured to allow Cloud Management Gateway traffic.

  • Go to Configuration Manager console / Administration / Site configuration / Servers and site system role
  • Select Site system with the Management Point role which you want to use for CMG
  • Right click on Management Point and select Properties
  • Ensure following settings are configured to allow internet traffics through CMG
  • Select Allow Configuration Manager cloud management gatway traffic
  • Select Allow intranet and internet connections if you want to use this management point for both internet and intranet clients
  • Select Allow internet only communication if you want to use this management point for internet clients only. You must have another management point to support intranet clients if selecting this option.

Allow Configuration Manager Cloud management gateway traffic | Management Point

Configure Software Update Point to Allow CMG Traffic

The Software Update Point need to be configured to allow Cloud Management Gateway traffic.

  • Go to Configuration Manager console / Administration / Site configuration / Servers and site system role
  • Select Site system with the Software Update Point role which you want to use for CMG
  • Right click on Software Update Point and select Properties
  • Ensure following settings are configured to allow internet traffics through CMG
  • Select Allow Configuration Manager cloud management gatway traffic
  • Select Allow Internet and intranet client connections if you want to use this management point for both internet and intranet clients
  • Select Allow internet only client connections if you want to use this software update point for internet clients only. You must have another software update point to support intranet clients if selecting this option.

Software Update Point | Allow Configuration Manager Cloud Management Gateway traffic

Configure Client Settings

In the SCCM console, go to Administration > Client Settings, select client settings name and go to Properties

Configure Following settings

Cloud Services

Enable client to use a cloud management gateway – Yes

Allow access to cloud distribution point – Yes

CMG Client Settings

Client Policy

Enable user policy requests from Internet client – Yes

CMG Client Settings

Nex post : Part 6 | Validate CMG Health & Client Communication

Related posts:

Subscribe to Techuisitive Newsletter

Be the first to know about our new blog posts. Get our newsletters directly in your inbox and stay up to date about Modern Desktop Management technologies & news.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top