<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>System Center Configuration Manager Team Blog</title><link>http://blogs.technet.com/configmgrteam/default.aspx</link><description>The official blog of the Microsoft System Center Configuration Manager Product Group</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Announcement: Configuration Manager Documentation Library Update for November 2009</title><link>http://blogs.technet.com/configmgrteam/archive/2009/11/23/announcement-configuration-manager-documentation-library-update-for-november-2009.aspx</link><pubDate>Mon, 23 Nov 2009 23:30:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3295919</guid><dc:creator>Configuration Manager Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/configmgrteam/comments/3295919.aspx</comments><wfw:commentRss>http://blogs.technet.com/configmgrteam/commentrss.aspx?PostID=3295919</wfw:commentRss><wfw:comment>http://blogs.technet.com/configmgrteam/rsscomments.aspx?PostID=3295919</wfw:comment><description>&lt;P&gt;&lt;EM&gt;[Today's post comes from the&amp;nbsp;&lt;/EM&gt;&lt;A href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx"&gt;&lt;EM&gt;Configuration Manager Writing Team&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt;]&lt;/EM&gt;&amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;The Configuration Manager documentation library (&lt;A href="http://technet.microsoft.com/en-us/library/bb680651.aspx"&gt;http://technet.microsoft.com/en-us/library/bb680651.aspx&lt;/A&gt;) has been updated on the Web and the latest content on the Web has &lt;B&gt;Updated: November 1, 2009&lt;/B&gt; at the top of the topic.&lt;/P&gt;
&lt;P mce_keep="true"&gt;This month's updates contain the latest supported configurations, as previously blogged here: &lt;A href="http://blogs.technet.com/configmgrteam/archive/2009/11/09/configuration-manager-support-announcements-for-november-2009.aspx"&gt;Configuration Manager Support Announcements for November 2009&lt;/A&gt;.&amp;nbsp; It also has some updates to existing documentation.&amp;nbsp; The additional support statements include Windows Storage Server&amp;nbsp;2003 and Windows Storage Server&amp;nbsp;2008 for distribution points, and support for running desired configuration management on Server Core with .Net Framework 2.0 installed.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;In addition to our support statements for BranchCache and DirectAccess with Configuration Manager&amp;nbsp;2007&amp;nbsp;SP2, we've added links to the official Windows Server documentation for these cross-technology dependencies:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;BranchCache: &lt;A href="http://go.microsoft.com/fwlink/?LinkId=177945" target=blank&gt;http://go.microsoft.com/fwlink/?LinkId=177945&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;DirectAccess: &lt;A href="http://go.microsoft.com/fwlink/?LinkId=178017" target=blank&gt;http://go.microsoft.com/fwlink/?LinkId=178017&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P mce_keep="true"&gt;We do value customer feedback and try to incorporate it when possible. &amp;nbsp;Although we can't promise to make the docs perfect for everybody, we are committed to continual improvement. &amp;nbsp;So, keep that feedback coming, and feel free to contact us about anything related to the documentation by using our usual address of &lt;A href="mailto:SMSDocs@Microsoft.com"&gt;SMSDocs@Microsoft.com&lt;/A&gt;.&amp;nbsp; &lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;What's New in the Configuration Manager Documentation Library for November 2009&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;The following information lists the topics that contain significant changes since the August 2009 update.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/ee344146.aspx"&gt;Configuration Manager 2007 SP2 Supported Configurations&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated to include the latest support statements.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc161851.aspx"&gt;Configuration Manager 2007 R2 Supported Configurations&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated to include the latest support statements.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc161823.aspx"&gt;Configuration Manager 2007 SP1 Supported Configurations&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated to include the latest support statements.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc161785.aspx"&gt;Prerequisites for Out of Band Management&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated with the latest WinRM support version information.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb694289.aspx"&gt;Configuration Manager Site to Site Communications&lt;/A&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb693782.aspx"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated to remove the following requirement: &amp;nbsp;"The Domain Admins group from the trusted Domain are added to the local administrators group on the Configuration Manager 2007 primary site servers spanning the trust." Customers brought to our attention that this requirement was not necessary.&amp;nbsp; We asked the product group to retest, and they confirmed that this requirement was not needed when there is a forest trust.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb632595.aspx"&gt;Predefined Maintenance Tasks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated with missing information about the new tasks:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Delete Aged Delete Detection Data&lt;/LI&gt;
&lt;LI&gt;Evaluate Provisioned AMT Computer Certificates&lt;/LI&gt;
&lt;LI&gt;Reset AMT Computer Passwords&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;This information has also been added to &lt;A href="http://technet.microsoft.com/en-us/library/bb693817.aspx"&gt;Predefined Maintenance Task Planning&lt;/A&gt;.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/ee344267.asp"&gt;How to Configure Hardlinks for User State Migration&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated to correct the procedure title.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb694155.aspx"&gt;Glossary term for fallback status point&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Modified to indicate that the fallback status point is not just for error conditions but is also useful in tracking successful client deployments.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb680347.as"&gt;How to Configure Network Discovery&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Corrected our favorite typo of the month - replacing "typology" with "topography".&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;-- &lt;A href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx"&gt;The Configuration Manager Writing Team&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;This posting is provided "AS IS" with no warranties and confers no rights.&lt;/I&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3295919" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/configmgrteam/archive/tags/Documentation/default.aspx">Documentation</category></item><item><title>Configuration Manager Support Announcements for November 2009</title><link>http://blogs.technet.com/configmgrteam/archive/2009/11/09/configuration-manager-support-announcements-for-november-2009.aspx</link><pubDate>Mon, 09 Nov 2009 21:44:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3292581</guid><dc:creator>Configuration Manager Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/configmgrteam/comments/3292581.aspx</comments><wfw:commentRss>http://blogs.technet.com/configmgrteam/commentrss.aspx?PostID=3292581</wfw:commentRss><wfw:comment>http://blogs.technet.com/configmgrteam/rsscomments.aspx?PostID=3292581</wfw:comment><description>&lt;P&gt;&lt;I&gt;[Today's post is provided by &lt;/I&gt;&lt;A href="http://blogs.technet.com/configmgrteam/pages/levi-stevens-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/levi-stevens-bio.aspx"&gt;&lt;I&gt;Levi Stevens&lt;/I&gt;&lt;/A&gt;&lt;I&gt;]&amp;nbsp; &lt;/I&gt;&lt;/P&gt;
&lt;P&gt;Up until now we have released support announcements on the &lt;A href="http://blogs.technet.com/configurationmgr/" mce_href="http://blogs.technet.com/configurationmgr/"&gt;ConfigMgr Support Team&lt;/A&gt; blog from our very own Customer Support Services.&amp;nbsp; Moving forward, we will be announcing support for new configuration via our &lt;A href="http://blogs.technet.com/configmgrteam/default.aspx" mce_href="http://blogs.technet.com/configmgrteam/default.aspx"&gt;Configuration Manager Team&lt;/A&gt; blog directly from our finger tips to your eyes.&amp;nbsp; While we are on the topic, you might be wondering what to expect from our team when new versions of our dependencies release.&amp;nbsp; First, let's establish some terminology.&amp;nbsp; We consider our ‘externals' anything that our product is dependent on (or specific features are dependent on) that is not developed by our own development teams.&amp;nbsp; We have dependencies on platforms like Windows or SQL, or components like .NET Framework or the Bandwidth Intelligent Throttling Service (BITS).&amp;nbsp; We currently track over 26 external dependencies against our product.&lt;/P&gt;
&lt;P&gt;Each time a new version of an external is going to release, our team assesses whether or not we will offer support for this new external. &amp;nbsp;Often this will involve some ‘scout' testing, some sanity check to see if there are any blatant issues and to size the cost to thoroughly test and validate the new release.&amp;nbsp; In some cases we need to release a hotfix to enable support, and in some cases we find no issues during test and can simply release a support statement.&amp;nbsp; As you can imagine the level of change affects our support approach.&amp;nbsp; For example, the release of Windows 7 required integration of a whole new WAIK and upgrading to a new toolset for imaging. This wasn't something that we could simply hotfix, so this level of support and change was rolled into our next service pack release (SP2 released on 10/22).&lt;/P&gt;
&lt;P&gt;You should look to our &lt;A href="http://technet.microsoft.com/en-us/library/bb680717.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb680717.aspx"&gt;Supported Configuration&lt;/A&gt; pages as your law for what is supported by Microsoft. In most cases we are specific about what we DO support, so if you are checking to see if a new Windows Service Pack is supported yet, if it is not listed, that means it is not supported.&amp;nbsp; When we do announce support, you can expect a new blog posting on our Configuration Manager Team blog and the official supported configuration page will be updated in the next document publishing cycle (quarterly).&lt;/P&gt;
&lt;P&gt;In a few cases we document support implicitly.&amp;nbsp; For example, we document that BITS 2.5 &lt;I&gt;as a minimum requirement &lt;/I&gt;in&lt;I&gt; &lt;/I&gt;the &lt;A href="http://technet.microsoft.com/en-us/library/bb694113.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb694113.aspx"&gt;ConfigMgr Prerequisites&lt;/A&gt;.&amp;nbsp; What does this mean when something such as BITS 4.0 releases? It means that our team is actively testing this new release and if we find issues we will document them.&lt;/P&gt;
&lt;P&gt;How does ‘extended support' or an expired service pack impact support for new configurations? &amp;nbsp;We do not test or add support for new configurations on a product that reaches extended support (like SMS 2003 coming in January) or with ConfigMgr 2007 RTM (with no service pack).&amp;nbsp; If your company is planning on rolling out new platforms or components you should plan moving to mainstream supported products and service pack levels.&lt;/P&gt;
&lt;P&gt;With that introduction, here are the support announcements for November 2009:&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Windows Storage Server 2008 is &lt;/B&gt;&lt;B&gt;now supported on Configuration Manager 2007 SP1 and SP2&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;System Center Configuration Manager 2007 SP1 and SP2 now support the Windows Storage Server 2008 operating systems for client installation.&amp;nbsp; Site system roles of a standard distribution point and a branch distribution point are supported.&amp;nbsp; Installations of the administrator console or other site system roles are not supported.&lt;/P&gt;
&lt;P mce_keep="true"&gt;No software updates are required.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Windows Remote Management (WinRM) 2.0 is now supported on Configuration Manager 2007 SP1 and SP2&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;System Center Configuration Manager 2007 SP1 and SP2 now support installing Windows Remote Management 2.0 on site systems running the out of band service point role.&lt;/P&gt;
&lt;P mce_keep="true"&gt;No software updates are required.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-- &lt;A href="http://blogs.technet.com/configmgrteam/pages/levi-stevens-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/levi-stevens-bio.aspx"&gt;Levi Stevens&lt;/A&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;I&gt;This posting is provided "AS IS" with no warranties and confers no rights.&lt;/I&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3292581" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/configmgrteam/archive/tags/Supported+Configurations/default.aspx">Supported Configurations</category></item><item><title>Configuration Manager 2007 Documentation Library Downloadable Quarterly Update for October 2009</title><link>http://blogs.technet.com/configmgrteam/archive/2009/11/06/configuration-manager-2007-documentation-library-downloadable-quarterly-update-for-october-2009.aspx</link><pubDate>Fri, 06 Nov 2009 18:44:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3292036</guid><dc:creator>Configuration Manager Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/configmgrteam/comments/3292036.aspx</comments><wfw:commentRss>http://blogs.technet.com/configmgrteam/commentrss.aspx?PostID=3292036</wfw:commentRss><wfw:comment>http://blogs.technet.com/configmgrteam/rsscomments.aspx?PostID=3292036</wfw:comment><description>&lt;P&gt;The latest downloadable quarterly update for the Configuration Manager 2007 Documentation Library has been posted to the download center. The October 2009 version is the newest downloadable update available and contains new material and fixes to documentation problems reported by customers since the last update was published for the April 2009 version. &lt;/P&gt;
&lt;P&gt;The January, April and October 2009 versions of the downloadable documentation help updates are now available on the Configuration Manager 2007 Help File Update Wizard download center page and additional, future quarterly updates will also be posted to this location.&lt;/P&gt;
&lt;P&gt;The eagle-eyed among you might notice that we did not publish a quarterly update for July 2009. This was because at this time the help file contained a lot of pre-release content for Configuration Manager 2007 SP2 that was subject to change.&lt;/P&gt;
&lt;P&gt;To get the most recent downloadable Configuration Manager Documentation Library help, go to &lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=71816b0f-de06-40e0-bce7-ad4b1e4377bb&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=71816b0f-de06-40e0-bce7-ad4b1e4377bb&amp;amp;displaylang=en&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;For more information about the Configuration Manager 2007 Help File Update Wizard, see this post: "Need the Latest Configuration Manager 2007 Help File?" at &lt;A href="http://blogs.technet.com/configmgrteam/archive/2009/02/03/need-the-latest-configuration-manager-2007-help-file.aspx"&gt;http://blogs.technet.com/configmgrteam/archive/2009/02/03/need-the-latest-configuration-manager-2007-help-file.aspx&lt;/A&gt; .&lt;/P&gt;
&lt;P&gt;Please contact &lt;A href="mailto:smsdocs@microsoft.com"&gt;smsdocs@microsoft.com&lt;/A&gt; if you have any questions or comments about this downloadable update.&lt;/P&gt;
&lt;P&gt;-- &lt;A href="http://blogs.technet.com/configmgrteam/pages/rob-stack-s-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/rob-stack-s-bio.aspx"&gt;Rob Stack&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;This posting is provided "AS IS" with no warranties and confers no rights.&lt;/EM&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3292036" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/configmgrteam/archive/tags/Documentation/default.aspx">Documentation</category></item><item><title>Announcement: Configuration Manager Documentation Library Update for October 2009</title><link>http://blogs.technet.com/configmgrteam/archive/2009/10/23/announcement-configuration-manager-documentation-library-update-for-october-2009.aspx</link><pubDate>Fri, 23 Oct 2009 18:16:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3288844</guid><dc:creator>Configuration Manager Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/configmgrteam/comments/3288844.aspx</comments><wfw:commentRss>http://blogs.technet.com/configmgrteam/commentrss.aspx?PostID=3288844</wfw:commentRss><wfw:comment>http://blogs.technet.com/configmgrteam/rsscomments.aspx?PostID=3288844</wfw:comment><description>&lt;EM&gt;[Today's post comes from the&amp;nbsp;&lt;/EM&gt;&lt;A href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx"&gt;&lt;FONT color=#0000cc&gt;&lt;EM&gt;Configuration Manager Writing Team&lt;/EM&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;EM&gt;]&lt;/EM&gt;&amp;nbsp; 
&lt;P&gt;The Configuration Manager documentation library (&lt;A href="http://technet.microsoft.com/en-us/library/bb680651.aspx"&gt;http://technet.microsoft.com/en-us/library/bb680651.aspx&lt;/A&gt;) has been updated on the Web and the latest content on the Web has &lt;B&gt;Updated: October 1, 2009&lt;/B&gt; at the top of the topic.&lt;/P&gt;
&lt;P mce_keep="true"&gt;This month's updates contain new content for Configuration Manager&amp;nbsp;2007&amp;nbsp;SP2 and some updates to existing documentation. It also includes a list of changes in the documentation since April 2009 (see &lt;A href="http://technet.microsoft.com/en-us/library/ee620254.aspx"&gt;What's New in the Configuration Manager Documentation Library for October 2009&lt;/A&gt;).&lt;/P&gt;
&lt;P mce_keep="true"&gt;We do value customer feedback and try to incorporate it when possible. &amp;nbsp;Although we can't promise to make the docs perfect for everybody, we are committed to continual improvement. So, keep that feedback coming, and feel free to contact us about anything related to the documentation by using our usual address of &lt;A href="mailto:SMSDocs@Microsoft.com"&gt;SMSDocs@Microsoft.com&lt;/A&gt;.&amp;nbsp; &lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;What's New in the Configuration Manager Documentation Library for October 2009&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;The following information lists the topics that contain significant changes since the August 2009 update.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc161823.aspx"&gt;Configuration Manager 2007 SP1 Supported Configurations&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated to include Windows Server&amp;nbsp;2008&amp;nbsp;R2 and Windows&amp;nbsp;7.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb633026.aspx"&gt;Supported Operating Systems and Hard Disk Configurations for Operating System Deployment&lt;/A&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb693755.aspx"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated with information about the operating systems that are not supported and those which can be deployed only by first capturing a Windows installation image (.wim) file using an image capture task sequence.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb693782.aspx"&gt;Supported Mobile Devices&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated to remove information about supported mobile device client operating systems so that it is now exclusively in supported configuration topics (&lt;A href="http://technet.microsoft.com/en-us/library/cc161860.aspx"&gt;Configuration Manager 2007 Supported Configurations&lt;/A&gt;). This means that customers have a consistent place to find supported version information and it reduces the risk of inconsistent information between topics.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb633103.aspx"&gt;About Heartbeat Discovery&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated to remove the incorrect information "Although you can configure Heartbeat Discovery to update client DDRs as frequently as you want, if you configure it to run less than once every 25 hours (the default client refresh cycle) the updated DDR will be reported no less than once every 25 hours". This restriction applied to an earlier version of the product and does not apply to Configuration Manager.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb680393.aspx"&gt;About the Site Repair Wizard&lt;/A&gt; and &lt;A href="http://technet.microsoft.com/en-us/library/bb632587.aspx"&gt;How to Back Up a Secondary Site&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated with the information that the Site Repair Wizard should not be used to recover a secondary site. The Product Group has confirmed that the recovery procedure doesn't work for secondary sites and will not be supported. If you need to recover a secondary site, reinstall it and secondary site configuration from the primary site will be replicated to it automatically when installation is complete. Because restoring a secondary site is not supported with the product, there is no point in backing up a secondary site by using the Backup Secondary Site Server maintenance task. To help avoid confusion, we have removed the procedural information in &lt;A href="http://technet.microsoft.com/en-us/library/bb632587.aspx"&gt;How to Back Up a Secondary Site&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;-- &lt;A href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx"&gt;&lt;FONT color=#0000cc&gt;The Configuration Manager Writing Team&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;This posting is provided "AS IS" with no warranties and confers no rights.&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3288844" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/configmgrteam/archive/tags/Documentation/default.aspx">Documentation</category></item><item><title>Configuration Manager 2007 Service Pack 2 Released</title><link>http://blogs.technet.com/configmgrteam/archive/2009/10/23/configuration-manager-2007-service-pack-2-released.aspx</link><pubDate>Fri, 23 Oct 2009 17:56:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3288843</guid><dc:creator>Configuration Manager Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/configmgrteam/comments/3288843.aspx</comments><wfw:commentRss>http://blogs.technet.com/configmgrteam/commentrss.aspx?PostID=3288843</wfw:commentRss><wfw:comment>http://blogs.technet.com/configmgrteam/rsscomments.aspx?PostID=3288843</wfw:comment><description>&lt;P&gt;We released Service Pack 2 for Configuration Manager 2007 yesterday.&amp;nbsp; See the release announcement by Jeff Wettlaufer &lt;A href="http://blogs.technet.com/systemcenter/archive/2009/10/22/configuration-manager-2007-service-pack-2-released.aspx"&gt;here&lt;/A&gt;.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;SP2 provides:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;B&gt;Windows 7 and Windows Server 2008 R2 support&lt;/B&gt; that enables customers to deploy and manage their Windows 7 client and server based systems.&lt;/LI&gt;
&lt;LI&gt;&lt;B&gt;New options for Out of Band Management &lt;/B&gt;that includes the addition of updated firmware support along with support for key new features such as wireless profile management and 802.1X.&lt;/LI&gt;
&lt;LI&gt;&lt;B&gt;Branch Cache support &lt;/B&gt;that enables customers to significantly reduce WAN utilization in branch office scenarios by leveraging new technology in Windows Server 2008 R2.&lt;/LI&gt;
&lt;LI&gt;&lt;B&gt;Greater 64-bit support&lt;/B&gt; that includes Remote Control, App-V, and the 2007 OpsMgr agent.&lt;/LI&gt;&lt;/UL&gt;
&lt;P mce_keep="true"&gt;For a full list&amp;nbsp;of what is included in SP2 see the &lt;A href="http://technet.microsoft.com/en-us/library/ee344318.aspx"&gt;What's New in Configuration Manager 2007 SP2&lt;/A&gt; topic in our documentation library.&amp;nbsp; The service pack can be downloaded &lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=3318741a-c038-4ab1-852a-e9c13f8a8140&amp;amp;displaylang=en"&gt;here&lt;/A&gt;.&amp;nbsp; A 180 day evaluation version of the service pack can be downloaded &lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=bad49573-6ad7-4521-a898-2ef99bc868c4&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=bad49573-6ad7-4521-a898-2ef99bc868c4&amp;amp;displaylang=en"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;We'd like to thank all our customers who participated in our beta program and provided feedback to us.&lt;/P&gt;
&lt;P mce_keep="true"&gt;--&lt;A href="http://blogs.technet.com/configmgrteam/pages/michael-cureton-s-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/michael-cureton-s-bio.aspx"&gt;&lt;FONT color=#0000cc&gt;Michael Cureton&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;This posting is provided "AS IS" with no warranties and confers no rights.&lt;/EM&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3288843" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/configmgrteam/archive/tags/SP2/default.aspx">SP2</category></item><item><title>Announcement: Configuration Manager Documentation Library Update for August 2009</title><link>http://blogs.technet.com/configmgrteam/archive/2009/08/20/announcement-configuration-manager-documentation-library-update-for-august-2009.aspx</link><pubDate>Thu, 20 Aug 2009 23:33:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3275393</guid><dc:creator>Configuration Manager Team</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/configmgrteam/comments/3275393.aspx</comments><wfw:commentRss>http://blogs.technet.com/configmgrteam/commentrss.aspx?PostID=3275393</wfw:commentRss><wfw:comment>http://blogs.technet.com/configmgrteam/rsscomments.aspx?PostID=3275393</wfw:comment><description>&lt;P&gt;&lt;EM&gt;[Today's post comes from the&amp;nbsp;&lt;/EM&gt;&lt;A href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx"&gt;&lt;FONT color=#0000cc&gt;&lt;EM&gt;Configuration Manager Writing Team&lt;/EM&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;EM&gt;]&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The Configuration Manager documentation library (&lt;A href="http://technet.microsoft.com/en-us/library/bb680651.aspx"&gt;http://technet.microsoft.com/en-us/library/bb680651.aspx&lt;/A&gt;) has been updated on the Web and the latest content&amp;nbsp;has &lt;B&gt;Updated: August 1, 2009&lt;/B&gt; at the top of the topic.&lt;/P&gt;
&lt;P mce_keep="true"&gt;We have only a handful of topics that have been updated this month to correct a couple of broken links and a minor editing clarification.&amp;nbsp; The main change that I want to draw your attention to is the addition of a single but very important sentence in &lt;A href="http://technet.microsoft.com/en-us/library/bb680733.aspx"&gt;Certificate Requirements for Native Mode&lt;/A&gt;, which is the following for each of the native mode certificates: &lt;B&gt;SHA-1 is the only supported hash algorithm&lt;/B&gt; &amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;When you install the Active Directory Certificate Services role on Windows Server 2008, the &lt;B&gt;Configure Cryptography for CA&lt;/B&gt; page of the Add Roles Wizard allows you to change the default hash algorithm of &lt;B&gt;sha1&lt;/B&gt; for other algorithms, such as those from the SHA2 family, including the stronger algorithms of SHA-256 and SHA-512. Only SHA-1 has been tested for native mode communication in Configuration Manager 2007, and there are no plans to extend this support in the near future.&amp;nbsp; Therefore, all native mode certificates must be issued by a CA that uses SHA-1.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P mce_keep="true"&gt;Disclaimer:&amp;nbsp; The procedures in this blog post are external to Configuration Manager, so you will not find this information in the Configuration Manager product documentation. &amp;nbsp;However, we realize that PKI is often new to Configuration Manager admins, and aim to share our knowledge and experience to help you be more successful with the product.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P mce_keep="true"&gt;How can you tell whether your certificates are using SHA-1 or another algorithm?&amp;nbsp; Check the properties of the issued certificate, by using the Certificates MMC.&amp;nbsp; In the Details tab, check the value of the &lt;B&gt;Signature algorithm&lt;/B&gt; - it should say &lt;B&gt;sha1RSA&lt;/B&gt;.&amp;nbsp; And on the issuing CA, check the properties of the CA, General Tab - it should display &lt;B&gt;Hash algorithm: sha1&lt;/B&gt; under the Cryptographic settings section. &lt;/P&gt;
&lt;P mce_keep="true"&gt;From customer feedback on the forums (and verified with our own testing), we know that when the site server signing certificate is signed with an algorithm that is higher than SHA-1, the MPControl.log file on the management point displays &lt;FONT size=2 face="Courier New"&gt;CryptVerifyCertificateSignatureEx returned error 0xc000a000&lt;/FONT&gt; instead of the expected &lt;FONT size=2 face="Courier New"&gt;CryptVerifyCertificateSignatureEx returned error 0x80090006.&lt;/FONT&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;If you have installed Active Directory Certificate Services with a hash algorithm other than SHA-1, you can reconfigure it to use SHA-1 by using the following procedure:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;From a command prompt on the server running the CA, type the following: Certutil&amp;nbsp;-setreg&amp;nbsp;ca\csp\CngHashAlgorithm&amp;nbsp;SHA1&lt;/LI&gt;
&lt;LI&gt;Stop and restart Certificate Services.&lt;/LI&gt;
&lt;LI&gt;If necessary, request and issue new certificates.&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;-- &lt;A href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx"&gt;The Configuration Manager Writing Team&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;This posting is provided "AS IS" with no warranties and confers no rights.&lt;/I&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3275393" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/configmgrteam/archive/tags/Documentation/default.aspx">Documentation</category></item><item><title>Updated Troubleshooting Information for Out of Band Management (SP1)</title><link>http://blogs.technet.com/configmgrteam/archive/2009/08/13/updated-troubleshooting-information-for-out-of-band-management-sp1.aspx</link><pubDate>Thu, 13 Aug 2009 20:32:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3273202</guid><dc:creator>Configuration Manager Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/configmgrteam/comments/3273202.aspx</comments><wfw:commentRss>http://blogs.technet.com/configmgrteam/commentrss.aspx?PostID=3273202</wfw:commentRss><wfw:comment>http://blogs.technet.com/configmgrteam/rsscomments.aspx?PostID=3273202</wfw:comment><description>&lt;P mce_keep="true"&gt;&lt;EM&gt;[Today's post is provided by &lt;/EM&gt;&lt;A href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx"&gt;&lt;FONT color=#0000cc&gt;&lt;EM&gt;Carol Bailey&lt;/EM&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;EM&gt;]&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;We have recently updated the Configuration Manager Documentation Library for out of band management for SP2, including revisions to troubleshooting issues.&amp;nbsp; Some of these revisions are also applicable to Configuration Manager 2007 SP1, but we can't publish them with our monthly updates because of the new SP2 content.&amp;nbsp; Rather than waiting until SP2 is released, I'm including the revisions here that affect existing customers using out of band management in Configuration Manager 2007 SP1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Configuration Manager Fails to Provision Computers with a Disjointed Namespace&lt;/H4&gt;
&lt;P&gt;Out of band management does not support AMT provisioning of computers that have a disjointed namespace. An example of a disjointed namespace is when an AMT-based computer has a DNS name of &lt;I&gt;computer1.corp.fabrikam.com&lt;/I&gt; and resides in an Active&amp;nbsp;Directory domain named &lt;I&gt;na.corp.fabrikam.com&lt;/I&gt; instead of in an Active&amp;nbsp;Directory domain named &lt;I&gt;corp.fabrikam.com&lt;/I&gt;.&lt;/P&gt;
&lt;H4&gt;Solution&lt;/H4&gt;
&lt;P&gt;There is no workaround to this requirement other than to align the DNS namespace with the Active&amp;nbsp;Directory namespace.&lt;/P&gt;
&lt;H4&gt;&amp;nbsp;&amp;nbsp;&lt;/H4&gt;
&lt;H4&gt;Computers Fail to Provision Out of Band Because the Computer Has Been Discovered by Configuration Manager&lt;/H4&gt;
&lt;P&gt;If out of band provisioning is used and the AMT-based computer has already been discovered by Configuration Manager before the provisioning process starts, provisioning fails with Configuration Manager 2007&amp;nbsp;SP1. In this scenario, after running the Import Computer for Out of Band Management Wizard, the site code is incorrectly missing from the client record, which causes provisioning to fail.&lt;/P&gt;
&lt;H4&gt;Solution&lt;/H4&gt;
&lt;P&gt;This issue is addressed with Configuration Manager 2007&amp;nbsp;SP2. If you cannot upgrade to Configuration Manager 2007&amp;nbsp;SP2, a workaround to complete out of band provisioning in this scenario is to delete the client record in the Configuration Manager console before running the Import Computer for Out of Band Management Wizard. Alternatively, use in-band provisioning.&lt;/P&gt;
&lt;H4&gt;&amp;nbsp;&amp;nbsp;&lt;/H4&gt;
&lt;H4&gt;The Out of Band Management Console Fails to Connect to AMT-Based Computers That Were Successfully Provisioned Out of Band and Do Not Have an Operating System Installed&lt;/H4&gt;
&lt;P&gt;If the computer running the out of band management console cannot connect to an AMT-based computer that was successfully provisioned out of band and that does not have an operating system installed, it might be because there is no host record in DNS to resolve the FQDN to the IP address of the AMT-based computer. There is no DNS client supplied with versions of AMT that are supported in Configuration Manager 2007&amp;nbsp;SP1 and later. Therefore, other methods must be used to create and update this record in DNS. When an operating system is installed, this can update DNS directly or through a DHCP record. However, when provisioning out of band, the initial host name of the AMT-based computer will be a factory default name and might be used on multiple computers rather than be unique. Although your choice of FQDN is written to AMT during the provisioning process, AMT cannot update the initial DHCP record with this new computer name. This results in name resolution failing for the FQDN when the out of band management console tries to connect to the AMT-based computer, and the following entry is logged in the &amp;lt;ConfigMgrInstallationPath&amp;gt;\AdminUI\AdminUILog\Oobconsole.log file: &lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;FONT size=2 face="Courier New"&gt;GetAMTPowerState fail with result: 0x800703E3&lt;/B&gt;&lt;/FONT&gt;&lt;B&gt; &lt;/B&gt;&lt;/P&gt;
&lt;H4&gt;Solution&lt;/H4&gt;
&lt;P&gt;When an operating system is installed with the same FQDN that was supplied during AMT provisioning, a host record will be added to DNS either directly or by using DHCP and out of band management communication will then succeed. To manage the AMT-based computer out of band before an operating system is installed, you must manually create host records in DNS for these computers that resolves their FQDN supplied in the Import Computer for Out of Band Management wizard to their current IP address in AMT. You can locate their current IP address from the BIOS extensions, or if you know the MAC address, you can find the corresponding IP address from DHCP.&lt;/P&gt;
&lt;P&gt;For new computers that are not yet provisioned for AMT, perform the following steps:&lt;/P&gt;
&lt;OL type=1&gt;
&lt;LI&gt;Create a DHCP reservation for this computer and supply the MAC address of the AMT-based computer.&lt;/LI&gt;
&lt;LI&gt;Manually create a host record in DNS such that the host name matches the FQDN supplied in the Import Computer for Out of Band Management wizard and the IP address matches the address in the DHCP reservation.&lt;/LI&gt;&lt;/OL&gt;
&lt;H4&gt;&amp;nbsp;&amp;nbsp;&lt;/H4&gt;
&lt;H4&gt;IDE Redirection Fails When the Out of Band Management Console Runs as a Low-Rights User&lt;/H4&gt;
&lt;P&gt;IDE redirection requires that the AMT administrator using the out of band management console has local administrator rights on the computer used to run the out of band management console when this computer supports user account control (UAC). For example, this includes Windows Vista and Windows Server&amp;nbsp;2008. &lt;/P&gt;
&lt;P&gt;To help identify this scenario, on the computer running the out of band management console, look for the following data in the Oobconsole.log file, with an entry that begins &lt;FONT size=2 face="Courier New"&gt;IMR_IDEROpenTCPSession&amp;lt;number&amp;gt; &lt;/FONT&gt;with &lt;FONT size=2 face="Courier New"&gt;user = &lt;/FONT&gt;and then contains user and drive information. This log file is located in the folder &amp;lt;ConfigMgrInstallationPath&amp;gt;\AdminUI\AdminUILog on the computer that runs the out of band management console.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;FONT size=2 face="Courier New"&gt;fail with result:0x2, description:Invalid Parameter&lt;/B&gt;&lt;/FONT&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;H4&gt;Solution&lt;/H4&gt;
&lt;P&gt;Add the user account to the local Administrators group on the computer running the out of band management console.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;--&lt;A href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx"&gt;&lt;FONT color=#0000cc&gt;Carol Bailey&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;I&gt;This posting is provided "AS IS" with no warranties, and confers no rights.&lt;/I&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3273202" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/configmgrteam/archive/tags/AMT/default.aspx">AMT</category><category domain="http://blogs.technet.com/configmgrteam/archive/tags/OOB/default.aspx">OOB</category></item><item><title>Updated Blog Post for How to Publish the CRL on a Separate Web Server – for Delta CRLs</title><link>http://blogs.technet.com/configmgrteam/archive/2009/08/13/updated-blog-post-for-how-to-publish-the-crl-on-a-separate-web-server-for-delta-crls.aspx</link><pubDate>Thu, 13 Aug 2009 19:50:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3273186</guid><dc:creator>Configuration Manager Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/configmgrteam/comments/3273186.aspx</comments><wfw:commentRss>http://blogs.technet.com/configmgrteam/commentrss.aspx?PostID=3273186</wfw:commentRss><wfw:comment>http://blogs.technet.com/configmgrteam/rsscomments.aspx?PostID=3273186</wfw:comment><description>&lt;EM&gt;[&lt;/EM&gt;&lt;A href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx"&gt;&lt;FONT color=#0000cc&gt;&lt;EM&gt;Carol Bailey&lt;/EM&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;EM&gt;&amp;nbsp;has updated her previous post "How to Publish the CRL on a Separate Web Server"]&lt;/EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 
&lt;P&gt;We've recently updated our blog post for publishing the CRL on a separate Web server because the instructions were missing the variable &amp;lt;DeltaCRLAllowed&amp;gt; in the paths, which is needed for delta CRLs.&lt;/P&gt;
&lt;P mce_keep="true"&gt;As a rule, I'm not fond of adding variables in documentation instructions when they are not needed for basic functionality, but this one is needed for delta CRLs.&amp;nbsp; I also added &amp;lt;CAName&amp;gt; so that you can publish CRLs from different CAs into the same location (for example, when you have a tiered CA hierarchy you must publish CRLs from each CA in the chain up to and including the root), and &amp;lt;CRLNameSuffix&amp;gt; according to best practices (&lt;A href="http://technet.microsoft.com/en-us/library/dd379469(WS.10).aspx"&gt;http://technet.microsoft.com/en-us/library/dd379469(WS.10).aspx&lt;/A&gt;).&lt;/P&gt;
&lt;P mce_keep="true"&gt;Updated: &lt;A href="http://blogs.technet.com/configmgrteam/archive/2009/05/01/how-to-publish-the-crl-on-a-separate-web-server.aspx"&gt;How to Publish the CRL on a Separate Web Server&lt;/A&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;--&lt;A href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx"&gt;&lt;FONT color=#0000cc&gt;Carol Bailey&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;I&gt;This posting is provided "AS IS" with no warranties, and confers no rights.&lt;/I&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;EM&gt;&lt;/EM&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3273186" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/configmgrteam/archive/tags/Certificates/default.aspx">Certificates</category><category domain="http://blogs.technet.com/configmgrteam/archive/tags/PKI/default.aspx">PKI</category></item><item><title>Recommended White Paper for Native Mode Customers:  Deploying and Managing PKI inside Microsoft (Microsoft IT Showcase)</title><link>http://blogs.technet.com/configmgrteam/archive/2009/08/13/recommended-white-paper-for-native-mode-customers-deploying-and-managing-pki-inside-microsoft-microsoft-it-showcase.aspx</link><pubDate>Thu, 13 Aug 2009 19:41:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3273182</guid><dc:creator>Configuration Manager Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/configmgrteam/comments/3273182.aspx</comments><wfw:commentRss>http://blogs.technet.com/configmgrteam/commentrss.aspx?PostID=3273182</wfw:commentRss><wfw:comment>http://blogs.technet.com/configmgrteam/rsscomments.aspx?PostID=3273182</wfw:comment><description>&lt;P mce_keep="true"&gt;&lt;EM&gt;[&lt;/EM&gt;&lt;A href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx"&gt;&lt;FONT color=#0000cc&gt;&lt;EM&gt;Carol Bailey&lt;/EM&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;EM&gt;&amp;nbsp;gives us a recommendation for PKI reading material]&lt;/EM&gt;&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Customers that are running Configuration Manager in native mode and support Internet-based client management might be interested in reading the following technical white paper that was originally published in 2005 but updated in June this year.&amp;nbsp; I particularly liked the section "Lessons Learned and Best Practices" -learning from the professionals is always a good use of time!&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Microsoft IT Showcase: Deploying and Managing PKI inside Microsoft&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Download Word document: &lt;A href="http://download.microsoft.com/download/9/1/0/910a19a0-d06e-4b2e-b41d-00cb4f7f4ab4/0022_PKI_TWP.doc"&gt;http://download.microsoft.com/download/9/1/0/910a19a0-d06e-4b2e-b41d-00cb4f7f4ab4/0022_PKI_TWP.doc&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Online Web version: &lt;A href="http://technet.microsoft.com/en-us/library/cc964304.aspx"&gt;http://technet.microsoft.com/en-us/library/cc964304.aspx&lt;/A&gt; &lt;/P&gt;
&lt;P mce_keep="true"&gt;--&lt;A href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx"&gt;&lt;FONT color=#0000cc&gt;Carol Bailey&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;I&gt;This posting is provided "AS IS" with no warranties, and confers no rights.&lt;/I&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3273182" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/configmgrteam/archive/tags/PKI/default.aspx">PKI</category></item><item><title>Updated Security Best Practices for Out of Band Management in Service Pack 1</title><link>http://blogs.technet.com/configmgrteam/archive/2009/08/05/updated-security-best-practices-for-out-of-band-management-in-service-pack-1.aspx</link><pubDate>Wed, 05 Aug 2009 21:10:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3270925</guid><dc:creator>Configuration Manager Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/configmgrteam/comments/3270925.aspx</comments><wfw:commentRss>http://blogs.technet.com/configmgrteam/commentrss.aspx?PostID=3270925</wfw:commentRss><wfw:comment>http://blogs.technet.com/configmgrteam/rsscomments.aspx?PostID=3270925</wfw:comment><description>&lt;EM&gt;[Today's post is provided by &lt;/EM&gt;&lt;A href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx"&gt;&lt;FONT color=#0000cc&gt;&lt;EM&gt;Carol Bailey&lt;/EM&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;EM&gt;]&lt;/EM&gt;&amp;nbsp; 
&lt;P&gt;We have recently updated the Configuration Manager Documentation Library for out of band management in Configuration Manager 2007&amp;nbsp;SP2, including revisions to security best practices.&amp;nbsp; Some of these revisions are also applicable to out of band management in Configuration Manager 2007 SP1, but we can't publish them with our monthly updates because of the new SP2 content.&amp;nbsp; Rather than waiting until SP2 is released, I'm including the revisions here that affect existing customers using out of band management in Configuration Manager 2007 SP1.&lt;/P&gt;
&lt;P&gt;We have also updated the recommended collection query for in-band provisioning. The previous query included computers with the AMT status of Not Provisioned and Detected. Note that Detected means AMT capability is detected but the out of band service point is unable to currently provision it for AMT because the AMT Remote Admin Account or the MEBx Account has been changed. This is usually an indication that you need to configure an AMT Provisioning and Discovery Account.&lt;/P&gt;
&lt;P&gt;The new query excludes Configuration Manager clients that are blocked or not approved.&amp;nbsp; As a security best practice, provision only computers that you trust.&amp;nbsp; Blocked clients and unapproved clients are deemed to be untrusted.&amp;nbsp; This security best practice will be enforced in Configuration Manager 2007 SP2, but it is not enforced with Configuration Manager 2007 SP1, so the revised query automatically excludes these computers.&amp;nbsp; The revised query to use for the collection configured for in-band provisioning is as follows:&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Courier New"&gt;Select SMS_R_System.* from SMS_R_System inner join SMS_CM_RES_COLL_SMS00001 on SMS_CM_RES_COLL_SMS00001.ResourceId = SMS_R_System.ResourceId where (AMTStatus = 1 or AMTStatus = 2) and SMS_CM_RES_COLL_SMS00001.IsApproved = 1 and SMS_CM_RES_COLL_SMS00001.IsBlocked = 0&lt;/FONT&gt;&lt;/P&gt;
&lt;H2&gt;&lt;A title=_Toc237151396 name=_Toc237151396&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;H2&gt;&lt;FONT size=3&gt;Security Best Practices for Out of Band Management in Configuration Manager 2007 SP1&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Request customized firmware before purchasing AMT-based computers&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp; Computers that can be managed out of band have BIOS extensions that can set customized values to significantly increase security when these computers are on your network. Check which BIOS extension settings are available from your computer manufacturer, and specify your choice of values. For more information, see &lt;A href="http://technet.microsoft.com/en-us/library/cc161878.aspx"&gt;Decide Whether You Need a Customized Firmware Image From Your Computer Manufacturer&lt;/A&gt;. If your AMT-based computers do not have the firmware values that you want to use, you might be able to manually specify them yourself. For more information about manually configuring the BIOS extensions, refer to the Intel documentation or the documentation from your computer manufacturer. You can also refer to the Intel vPro Expert Center: Microsoft vPro Manageability Web site (&lt;A href="http://go.microsoft.com/fwlink/?LinkId=132001"&gt;http://go.microsoft.com/fwlink/?LinkId=132001&lt;/A&gt;). Customize the following options to increase your security:&lt;/P&gt;
&lt;UL class=unIndentedList&gt;
&lt;LI&gt;&lt;STRONG&gt;Replace all certificate thumbprints of external certification authorities (CAs) with the certificate thumbprint of your own internal CA.&lt;/STRONG&gt; This prevents rogue provisioning servers from attempting to provision your AMT-based computers, and you will not have to purchase provisioning certificates from external CAs. For information about how to locate the certificate thumbprint of your internal root CA, see &lt;A href="http://technet.microsoft.com/en-us/library/cc431407.aspx"&gt;How to Locate the Certificate Thumbprint of Your Internal Root Certificate for AMT Provisioning&lt;/A&gt;. &lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Use a custom password for the MEBx Account so that the default value of admin is not used.&lt;/STRONG&gt; Then specify this password with an AMT Provisioning and Discovery Account in Configuration Manager. This prevents rogue provisioning servers from attempting to provision your AMT-based computers with the known default password. For more information, see &lt;A href="http://technet.microsoft.com/en-us/library/cc431452.aspx"&gt;About the MEBx Account&lt;/A&gt; and &lt;A href="http://technet.microsoft.com/en-us/library/cc431431.aspx"&gt;How to Add an AMT Provisioning and Discovery Account&lt;/A&gt;. &lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Change the value for the default provisioning server.&lt;/STRONG&gt; Using the default name of ProvisionServer could present a security risk if a record with this name is configured to resolve to an IP address of the wrong computer or a rogue computer. Configuring the provisioning server value with an IP address is more secure than using a well-known name. However, an IP address cannot be used for multiple AMT-based computers if they will be provisioned by different sites. If you configure an alternative name rather than an IP address, you must configure DNS to perform name resolution. When you use name resolution for either &lt;STRONG&gt;ProvisionServer&lt;/STRONG&gt; or a custom name, secure the DNS record to safeguard against the record being modified in such a way that it no longer resolves to the out of band service point site system computer. For more information, see &lt;A href="http://technet.microsoft.com/en-us/library/cc161768.aspx"&gt;Decide Whether You Should Register an Alias for the Out of Band Service Point in DNS&lt;/A&gt;. &lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Configure an alternate port for server provisioning.&lt;/STRONG&gt; Using a custom port is more secure than using the default port for out of band provisioning. If you will use out of band provisioning, configure your alternative port number on the &lt;STRONG&gt;Out of Band Management Properties: General&lt;/STRONG&gt; tab.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Use in-band provisioning instead of out of band provisioning&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Using in-band provisioning, especially in native mode, allows the client to use the trust relationship already established between the client and the Configuration Manager infrastructure. With out of band provisioning, untrusted computers can be provisioned if they supply the SMBIOS GUID (also known as the UUID) that has been specified in the Import Out of Band Computers wizard. Successfully provisioned computers have an account automatically created in Active Directory Domain Services and receive a certificate with server authentication capability from your enterprise CA. If a rogue computer is provisioned, the resulting network authentication results in an elevation of privileges and the account could be used to read information on the network that is secured for authenticated access (information disclosure). A certificate with server authentication might be misused to establish trust. It is also possible for attackers to create servers that impersonate valid DNS servers and provisioning servers so that AMT-based computers are misdirected to rogue provisioning servers. If you do not need to use out of band provisioning, do the following to help reduce these security risks:&lt;/P&gt;
&lt;UL class=unIndentedList&gt;
&lt;LI&gt;To help prevent rogue computers from being provisioned out of band: Do not use the Import Out of Band Computers wizard to add new computers to the Configuration Manager database; configure Windows firewall on the server running the out of band service point role to block the provisioning port (by default, TCP 9971); and do not register an alias for the out of band service point in DNS. For more information about the DNS alias, see &lt;A href="http://technet.microsoft.com/en-us/library/cc161768.aspx"&gt;Decide Whether You Should Register an Alias for the Out of Band Service Point in DNS&lt;/A&gt;. Additionally, restrict physical access to the network, and monitor clients to detect unauthorized computers. &lt;/LI&gt;
&lt;LI&gt;To help prevent rogue servers from provisioning your AMT-based computers, use a custom password for the MEBx Account in the AMT BIOS extensions so that the default value of &lt;STRONG&gt;admin&lt;/STRONG&gt; is not used. Then specify this password with an AMT Provisioning and Discovery Account in Configuration Manager. For more information, see &lt;A href="http://technet.microsoft.com/en-us/library/cc431452.aspx"&gt;About the MEBx Account&lt;/A&gt; and &lt;A href="http://technet.microsoft.com/en-us/library/cc431431.aspx"&gt;How to Add an AMT Provisioning and Discovery Account&lt;/A&gt;. &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;If you cannot use in-band provisioning because the computer is new and has no operating system installed, consider using operating system deployment to install the operating system and install the Configuration Manager 2007 SP1 client so that the computer can be provisioned in-band. Unlike out of band provisioning, operating system deployment does not create an authenticated account in Active Directory Domain Services and does not request a server authentication certificate from your enterprise CA. For more information about operating system deployment, see &lt;A href="http://technet.microsoft.com/en-us/library/bb632767.aspx"&gt;Operating System Deployment in Configuration Manager&lt;/A&gt;. If you cannot use in-band provisioning because the computer does not have the Configuration Manager 2007 SP1 client installed or because the computer does not have a version of AMT that is natively supported by Configuration Manager, install the Configuration Manager 2007 SP1 client and upgrade the firmware to a supported version as appropriate. For more information about the AMT versions supported by Configuration Manager, see &lt;A href="http://technet.microsoft.com/en-us/library/cc161963.aspx"&gt;Overview of Out of Band Management&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Manually revoke certificates and delete Active Directory accounts for AMT-based computers that are blocked by a Configuration Manager 2007 SP1 site&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp; Computers that are blocked by a Configuration Manager 2007 SP1 site continue to accept out of band management communication. When an AMT-based computer is blocked because it is no longer trusted, take the following manual action:&lt;/P&gt;
&lt;UL class=unIndentedList&gt;
&lt;LI&gt;On the issuing CA, revoke the certificate that was issued to the site server with the FQDN of the AMT-based computer in the certificate Subject. &lt;/LI&gt;
&lt;LI&gt;In Active Directory Domain Services, disable or delete the AMT account that was created for the AMT-based computer.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Control the request and installation of the provisioning certificate&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Request the provisioning certificate directly from the provisioning server by using the computer security context so that the certificate is installed directly into the local computer store. If you must request the certificate from another computer, you will have to export the private key and then use additional security controls while transferring and importing the certificate into a certificate store with restricted access. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Ensure that you request a new provisioning certificate before the existing certificate expires&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; An expired AMT provisioning certificate will result in provisioning failure. If you are using an external CA for your provisioning certificate, allow additional time to complete the renewal process and reconfigure the out of band management point. &lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Note &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;To help you identify when the AMT provisioning certificate is about to expire, Configuration Manager generates a warning status message with ID 7210 when the provisioning certificate in use is 40 days or less from expiration. This status message will be repeated once a day until the certificate is replaced with a validity period greater than 40 days or until the validity period is less than 15 days. When the validity period is less than 15 days, an error status message with ID 7211 is generated until the certificate is replaced with a validity period greater than 15 days.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;If the provisioning certificate is revoked, delete it from the certificate store on the out of band service point site system server, and remove it from the out of band management component configuration properties&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; If you know that the AMT provisioning certificate is revoked, you must manually prevent it from being used to provision AMT-based computers by Configuration Manager because AMT-based computers do not check the CRL for the provisioning certificate. Delete the certificate from the certificate store on the out of band service point site system server. Then deploy a new provisioning certificate, and configure it in the &lt;STRONG&gt;Out of Band Management Properties&lt;/STRONG&gt; dialog box. If you cannot immediately deploy a valid AMT provisioning certificate, remove the out of band service point role until you have a replacement certificate.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If you must revoke a provisioning certificate supplied by an internal CA, revoke the certificate in the Certification Authority console&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; There is no functionality to revoke the provisioning certificate in Configuration Manager 2007 SP1.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Use a dedicated certificate template for provisioning AMT-based computers&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp; If you are using an Enterprise version of Windows Server for your enterprise CA, create a new certificate template by duplicating the default Web Server certificate template, ensure that only Configuration Manager site servers have Read and Enroll permissions, and do not add additional capabilities to the default of server authentication. Having a dedicated certificate template allows you to better manage and control access to help prevent elevation of privileges. If you have a Standard version of Windows Server for your enterprise CA, you will not be able to create a duplicate certificate template. In this scenario, do not allow Read and Enroll permissions to computers other than Configuration Manager site servers that will provision AMT-based computers.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Use out of band management instead of Wake On LAN&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Although both solutions support waking up computers for software updates and advertisements, out of band management is a more secure solution than Wake On LAN because it provides authentication and encryption using standard industry security protocols. It can also integrate with an existing public key infrastructure (PKI) deployment, and the security controls can be managed independently from the product. For more information, see &lt;A href="http://technet.microsoft.com/en-us/library/cc161828.aspx"&gt;Choose Between Power On Commands with Out of Band Management and Wake-Up Packets for Wake On LAN&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Use a dedicated OU to publish AMT-based computers&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Do not use an existing container or OU to publish the Active Directory accounts that are created during AMT provisioning. A separate OU allows you to better manage and control these accounts and helps to ensure that they are not granted more privileges than they need.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Use Group Policy to Restrict User Rights for the AMT Accounts&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Apply restrictive user rights to the AMT accounts that are published to Active Directory Domain Services to help protect against elevation of privileges and to reduce the attack surface if an attacker gains access to one of these accounts. Create a security group that contains the AMT accounts automatically created by Configuration Manager during the ATM provisioning process, and then add this group to the following enabled group policy settings under \Computer Configuration\Windows Settings\Security Settings\Local Policy\User Rights Assignment:&lt;/P&gt;
&lt;UL class=unIndentedList&gt;
&lt;LI&gt;Deny access to this computer from the network &lt;/LI&gt;
&lt;LI&gt;Deny log on as a batch job &lt;/LI&gt;
&lt;LI&gt;Deny log on as a service &lt;/LI&gt;
&lt;LI&gt;Deny log on locally &lt;/LI&gt;
&lt;LI&gt;Deny log on through Terminal Services&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Apply these group policy settings to all computers in the forest. Periodically review and revise if necessary the group membership to ensure that it contains all the AMT accounts currently published to Active Directory Domain Services.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Use a dedicated collection for in-band provisioning&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Do not use an existing collection that contains more computers than you want to provision in-band. Instead, create a query-based collection by using the procedure for in-band provisioning in &lt;A href="http://technet.microsoft.com/en-us/library/cc161856.aspx"&gt;How to Provision Computers for AMT&lt;/A&gt;. When the site is in mixed mode, ensure that these computers are approved. For more information about approval, see &lt;A href="http://technet.microsoft.com/en-us/library/bb694193.aspx"&gt;About Client Approval in Configuration Manager&lt;/A&gt; and &lt;A href="http://technet.microsoft.com/en-us/library/bb633214.aspx"&gt;How to Approve Configuration Manager Clients&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Restrict who has the Media Redirection right and the PT Administration right&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp; Granting someone the Media Redirection right is almost equivalent to granting someone physical access to the computer. While attackers still require physical access to open the computer, someone with the Media Redirection right could load an alternate operating system and use it to remotely attack data on the hard drive. The PT Administration right automatically includes all AMT rights, which includes the Media Redirection right.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Retrieve and store image files securely when booting from alternative media to use the IDE redirection function&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp; When you boot from alternative media to use the IDE redirection function, whenever possible, store the image files locally on the computer running the out of band management console. If you must store them on the network, ensure that connections to retrieve the files over the network use SMB signing to help prevent the files being tampered with during the network transfer. In both scenarios, secure the stored files to help prevent unauthorized access (for example, using NTFS permissions and the encrypted file system).&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Minimize the number of AMT Provisioning and Discovery Accounts&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp; Although you can specify multiple AMT Provisioning and Discovery Accounts so that Configuration Manager can discover computers that have management controllers and provision them for out of band management, do not specify accounts that are not currently required and delete accounts that are no longer needed. Specifying only the accounts that you need helps to ensure that these accounts are not granted more privileges than they need and helps to reduce unnecessary network traffic and processing. For more information about the AMT Provisioning and Discovery Account, see &lt;A href="http://technet.microsoft.com/en-us/library/cc431451.aspx"&gt;Determine Whether to Configure an AMT Provisioning and Discovery Account for Out of Band Management&lt;/A&gt; and &lt;A href="http://technet.microsoft.com/en-us/library/cc431409.aspx"&gt;About the AMT Provisioning and Discovery Account&lt;/A&gt;.&lt;/P&gt;
&lt;P mce_keep="true"&gt;--&lt;A href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx"&gt;&lt;FONT color=#0000cc&gt;Carol Bailey&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;I&gt;This posting is provided "AS IS" with no warranties, and confers no rights.&lt;/I&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3270925" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/configmgrteam/archive/tags/AMT/default.aspx">AMT</category><category domain="http://blogs.technet.com/configmgrteam/archive/tags/OOB/default.aspx">OOB</category><category domain="http://blogs.technet.com/configmgrteam/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/configmgrteam/archive/tags/Best+Practice/default.aspx">Best Practice</category></item><item><title>Announcement: Configuration Manager Documentation Library Update for July 2009</title><link>http://blogs.technet.com/configmgrteam/archive/2009/07/29/announcement-configuration-manager-documentation-library-update-for-july-2009.aspx</link><pubDate>Wed, 29 Jul 2009 22:31:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3269170</guid><dc:creator>Configuration Manager Team</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.technet.com/configmgrteam/comments/3269170.aspx</comments><wfw:commentRss>http://blogs.technet.com/configmgrteam/commentrss.aspx?PostID=3269170</wfw:commentRss><wfw:comment>http://blogs.technet.com/configmgrteam/rsscomments.aspx?PostID=3269170</wfw:comment><description>&lt;P&gt;&lt;EM&gt;[Today's Post is provided by &lt;/EM&gt;&lt;A href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx"&gt;&lt;EM&gt;the Configuration Manager Writing Team&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt;]&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The Configuration Manager documentation library (&lt;A href="http://technet.microsoft.com/en-us/library/bb680651.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb680651.aspx"&gt;http://technet.microsoft.com/en-us/library/bb680651.aspx&lt;/A&gt;) has been updated on the Web and the following information lists the topics that are new or contain significant changes since the June 2009 update. &amp;nbsp;The latest content that has been updated on the Web has &lt;B&gt;Updated: July 1, 2009&lt;/B&gt; at the top of the topic.&lt;/P&gt;
&lt;P mce_keep="true"&gt;We don't have as many updates for you this month, because we've been working on documentation for Service Pack 2 (to be included with Configuration Manager 2007 SP2 RC) and the SuperFlows. &amp;nbsp;The updates that we have come from customer feedback. &amp;nbsp;Although we can't promise to make the docs perfect for everybody, we are committed to continual improvement. So, keep that feedback coming, and feel free to contact us about anything related to the documentation by using our usual address of &lt;A href="mailto:SMSDocs@Microsoft.com" mce_href="mailto:SMSDocs@Microsoft.com"&gt;SMSDocs@Microsoft.com&lt;/A&gt;.&amp;nbsp; &lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;What's New in the Configuration Manager Documentation Library for July 2009&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;The following information lists the topics that are new or contain significant changes since the June 2009 update:&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd547071.aspx" mce_href="http://technet.microsoft.com/en-us/library/dd547071.aspx"&gt;Configuration Manager 2007 General Supported Configurations&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated to include the support statement that Configuration Manager clients are not support with Network Address Translation (NAT), unless the site is configured for Internet-based client management and the client detects that it is on the Internet.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc161823.aspx" mce_href="http://technet.microsoft.com/en-us/library/cc161823.aspx"&gt;Configuration Manager 2007 SP1 Supported Configurations&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated to include a feature section for Out of Band Management. &amp;nbsp;This includes the versions of AMT that are supported, operating system limitations for the out of band management console, and the support statement that out of band communication to an AMT-based computer is not supported if it is running the Routing and Remote Access service in the client operating system.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb932144.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb932144.aspx"&gt;Troubleshooting General Operating System Deployment Issues&lt;/A&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc431360.aspx" mce_href="http://technet.microsoft.com/en-us/library/cc431360.aspx"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated with the new entry "Security Registry Keys for Native Mode Remain in Captured Images". &amp;nbsp;This issue was reported in the &lt;A href="http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/3ac574ca-c562-4a44-92da-5c640a71c3c6" mce_href="http://social.technet.microsoft.com/Forums/en-US/configmgribcm/thread/3ac574ca-c562-4a44-92da-5c640a71c3c6"&gt;forums&lt;/A&gt; when a customer used a captured image from a native mode client that used a different CA hierarchy to the one used on the production network, and it resulted in the client being unmanaged.&amp;nbsp; This troubleshooting entry includes the prescribed additional steps to take if you capture an image from a native mode client.&amp;nbsp; .&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb932192.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb932192.aspx"&gt;Troubleshooting Task Sequence Initiated Operating System Deployment Issues&lt;/A&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc431360.aspx" mce_href="http://technet.microsoft.com/en-us/library/cc431360.aspx"&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated with the new entry "Task Sequence Always Performs Certificate Revocation Checking in Native Mode Site". &amp;nbsp;This issue documents how to identify a known issue with task sequences always checking the CRL in a native mode site, even after following the procedures to disable CRL checking on clients.&amp;nbsp; In this scenario, if the CRL cannot be accessed, all native mode communication will fail and the smsts.log file will record: WINHTTP_CALLBACK_STATUS_FLAG_CERT_REV_FAILED.&lt;/P&gt;
&lt;P&gt;-- &lt;A href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx"&gt;The Configuration Manager Writing Team&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;This posting is provided "AS IS" with no warranties and confers no rights.&lt;/I&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3269170" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/configmgrteam/archive/tags/Documentation/default.aspx">Documentation</category></item><item><title>Announcement: Some Configuration Manager SP1 hotfixes have been re-released for Windows Server 2008 SP2 and Windows Vista SP2</title><link>http://blogs.technet.com/configmgrteam/archive/2009/06/30/announcement-configuration-manager-sp1-hotfixes-have-been-re-released-for-windows-server-2008-sp2-and-windows-vista-sp2.aspx</link><pubDate>Wed, 01 Jul 2009 00:00:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3260127</guid><dc:creator>Configuration Manager Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/configmgrteam/comments/3260127.aspx</comments><wfw:commentRss>http://blogs.technet.com/configmgrteam/commentrss.aspx?PostID=3260127</wfw:commentRss><wfw:comment>http://blogs.technet.com/configmgrteam/rsscomments.aspx?PostID=3260127</wfw:comment><description>&lt;P&gt;&lt;I&gt;[Today's post is provided by &lt;A href="http://blogs.technet.com/configmgrteam/pages/yvette-o-meally-s-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/yvette-o-meally-s-bio.aspx"&gt;Yvette O'Meally&lt;/A&gt;]&lt;/I&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;The Configuration Manager Sustained Engineering team has re-released a number of Configuration Manager SP1 hotfixes due to a problem with the hotfix installer's ability to detect Windows Server 2008 SP2 and Windows Vista SP2.&amp;nbsp; This will cause Configuration Manager 2007 SP1 hotfixes to fail to install on those operating systems even though they are applicable.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;STRONG&gt;Symptoms&lt;/STRONG&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;If you try to install the original version of one of these Configuration Manager hotfixes on a system running Windows Server 2008 SP2 or Windows Vista SP2 you will get a popup with an error like this "This KB###### is for a different hardware platform." where ###### is the KB number of the hotfix you are installing.&amp;nbsp; The hotfix will fail to install.&lt;/P&gt;
&lt;P mce_keep="true"&gt;Entries similar to the following would be displayed in the KB######.log file&lt;/P&gt;&lt;PRE&gt;&lt;PRE style="FONT-SIZE: 11px; MARGIN: 0em; WIDTH: 100%; FONT-FAMILY: consolas,'Courier New',courier,monospace; BACKGROUND-COLOR: #ffffff"&gt;0.171: CheckSystem: GetMachineType failed :STATUS_PLATFORM_MISMATCH
&lt;/PRE&gt;&lt;PRE style="FONT-SIZE: 11px; MARGIN: 0em; WIDTH: 100%; FONT-FAMILY: consolas,'Courier New',courier,monospace; BACKGROUND-COLOR: #ffffff"&gt;0.171: DoInstallation: CheckSystem Failed: 0xf00e 
&lt;/PRE&gt;&lt;PRE style="FONT-SIZE: 11px; MARGIN: 0em; WIDTH: 100%; FONT-FAMILY: consolas,'Courier New',courier,monospace; BACKGROUND-COLOR: #ffffff"&gt;0.187: This KB957255 &lt;SPAN style="COLOR: #0000ff"&gt;is&lt;/SPAN&gt; &lt;SPAN style="COLOR: #0000ff"&gt;for&lt;/SPAN&gt; a different hardware platform.
&lt;/PRE&gt;&lt;PRE style="FONT-SIZE: 11px; MARGIN: 0em; WIDTH: 100%; FONT-FAMILY: consolas,'Courier New',courier,monospace; BACKGROUND-COLOR: #ffffff"&gt;1.575: Message displayed to the user: This KB957255 &lt;SPAN style="COLOR: #0000ff"&gt;is&lt;/SPAN&gt; &lt;SPAN style="COLOR: #0000ff"&gt;for&lt;/SPAN&gt; a different hardware platform.
&lt;/PRE&gt;&lt;PRE style="FONT-SIZE: 11px; MARGIN: 0em; WIDTH: 100%; FONT-FAMILY: consolas,'Courier New',courier,monospace; BACKGROUND-COLOR: #ffffff"&gt;1.575: User Input: OK
&lt;/PRE&gt;&lt;PRE style="FONT-SIZE: 11px; MARGIN: 0em; WIDTH: 100%; FONT-FAMILY: consolas,'Courier New',courier,monospace; BACKGROUND-COLOR: #ffffff"&gt;1.575: Update.exe extended &lt;SPAN style="COLOR: #0000ff"&gt;error&lt;/SPAN&gt; code = 0xf00e
&lt;/PRE&gt;&lt;PRE style="FONT-SIZE: 11px; MARGIN: 0em; WIDTH: 100%; FONT-FAMILY: consolas,'Courier New',courier,monospace; BACKGROUND-COLOR: #ffffff"&gt;1.575: Update.exe return code was masked to 0x643 &lt;SPAN style="COLOR: #0000ff"&gt;for&lt;/SPAN&gt; MSI custom action compliance.
&lt;/PRE&gt;&lt;PRE style="FONT-SIZE: 11px; MARGIN: 0em; WIDTH: 100%; FONT-FAMILY: consolas,'Courier New',courier,monospace; BACKGROUND-COLOR: #ffffff"&gt;&lt;/PRE&gt;&lt;/PRE&gt;
&lt;P mce_keep="true"&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If you have downloaded a Configuration Manager 2007 SP1 hotfix before June 16&lt;SUP&gt;th&lt;/SUP&gt; 2009 &lt;B&gt;and&lt;/B&gt; you have either Windows Server 2008 SP2 or Windows Vista SP2 you will need to obtain the repackaged version of the hotfix.&amp;nbsp; The affected hotfixes are listed in the table below.&lt;/P&gt;
&lt;P mce_keep="true"&gt;Please note that the product binaries inside the hotfix package are not affected.&amp;nbsp; The only changes are to the hotfix installer.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class=class cellSpacing=0 cellPadding=0 width=495 border=1 class="class"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P align=center&gt;&lt;STRONG&gt;KB&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P align=center&gt;&lt;STRONG&gt;Version Number&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P align=center&gt;&lt;STRONG&gt;Date/Time&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P align=center&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/954214" mce_href="http://support.microsoft.com/kb/954214"&gt;954214&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1101&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 1:00am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/954474" mce_href="http://support.microsoft.com/kb/954474"&gt;954474&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1102&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 1:05am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/954716" mce_href="http://support.microsoft.com/kb/954716"&gt;954716&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1103&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 2:10am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/955114" mce_href="http://support.microsoft.com/kb/955114"&gt;955114&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1105&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 2:20am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/955355" mce_href="http://support.microsoft.com/kb/955355"&gt;955355&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1107&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 2:30am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/955388" mce_href="http://support.microsoft.com/kb/955388"&gt;955388&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1108&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 2:35am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/955842" mce_href="http://support.microsoft.com/kb/955842"&gt;955842&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1109&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 2:40am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/955955" mce_href="http://support.microsoft.com/kb/955955"&gt;955955&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1110&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 2:45am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/955126" mce_href="http://support.microsoft.com/kb/955126"&gt;955126&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1111&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 2:50am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/956465" mce_href="http://support.microsoft.com/kb/956465"&gt;956465&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1112&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 2:55am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/956337" mce_href="http://support.microsoft.com/kb/956337"&gt;956337&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1113&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 3:00am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/956194" mce_href="http://support.microsoft.com/kb/956194"&gt;956194&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1114&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 3:05am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/954718" mce_href="http://support.microsoft.com/kb/954718"&gt;954718&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1115&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 3:10am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/955262" mce_href="http://support.microsoft.com/kb/955262"&gt;955262&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1117&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 3:20am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/956918" mce_href="http://support.microsoft.com/kb/956918"&gt;956918&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1118&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 3:25am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/956944" mce_href="http://support.microsoft.com/kb/956944"&gt;956944&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1119&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 3:30am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/956733" mce_href="http://support.microsoft.com/kb/956733"&gt;956733&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1120&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 3:35am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/956941" mce_href="http://support.microsoft.com/kb/956941"&gt;956941&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1121&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 3:40am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/957183" mce_href="http://support.microsoft.com/kb/957183"&gt;957183&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1122&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 3:45am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/957325" mce_href="http://support.microsoft.com/kb/957325"&gt;957325&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1123&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 3:50am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/957255" mce_href="http://support.microsoft.com/kb/957255"&gt;957255&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1124&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 3:55am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/957879" mce_href="http://support.microsoft.com/kb/957879"&gt;957879&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1125&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 4:00am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/957469" mce_href="http://support.microsoft.com/kb/957469"&gt;957469&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1126&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 4:05am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/957576" mce_href="http://support.microsoft.com/kb/957576"&gt;957576&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1127&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 4:10am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/955115" mce_href="http://support.microsoft.com/kb/955115"&gt;955115&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1128&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 4:15am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/958808" mce_href="http://support.microsoft.com/kb/958808"&gt;958808&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1129&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 4:20am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/959040" mce_href="http://support.microsoft.com/kb/959040"&gt;959040&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1130&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 4:25am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/959038" mce_href="http://support.microsoft.com/kb/959038"&gt;959038&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1131&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 4:30am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/958021" mce_href="http://support.microsoft.com/kb/958021"&gt;958021&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1132&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 4:35am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/959257" mce_href="http://support.microsoft.com/kb/959257"&gt;959257&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1133&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 4:40am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/959700" mce_href="http://support.microsoft.com/kb/959700"&gt;959700&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1134&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 4:45am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/959812" mce_href="http://support.microsoft.com/kb/959812"&gt;959812&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1135&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 4:50am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/959875" mce_href="http://support.microsoft.com/kb/959875"&gt;959875&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1136&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 4:55am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/960448" mce_href="http://support.microsoft.com/kb/960448"&gt;960448&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1137&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 5:00am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/960741" mce_href="http://support.microsoft.com/kb/960741"&gt;960741&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1138&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 5:05am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/960634" mce_href="http://support.microsoft.com/kb/960634"&gt;960634&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1139&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 5:10am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/960846" mce_href="http://support.microsoft.com/kb/960846"&gt;960846&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1140&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 5:15am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=103 class="class"&gt;
&lt;P&gt;&lt;B&gt;&lt;A href="http://support.microsoft.com/kb/960804" mce_href="http://support.microsoft.com/kb/960804"&gt;960804&lt;/A&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=168 class="class"&gt;
&lt;P&gt;4.0.6221.1141&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top noWrap align=middle width=222 class="class"&gt;
&lt;P&gt;12/01/2008 5:20am&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P mce_keep="true"&gt;Thanks&lt;/P&gt;
&lt;P&gt;--&lt;A href="http://blogs.technet.com/configmgrteam/pages/yvette-o-meally-s-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/yvette-o-meally-s-bio.aspx"&gt;Yvette O'Meally&lt;/A&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;I&gt;This posting is provided "AS IS" with no warranties and confers no rights.&lt;/I&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3260127" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/configmgrteam/archive/tags/troubleshooting/default.aspx">troubleshooting</category><category domain="http://blogs.technet.com/configmgrteam/archive/tags/hotfixes/default.aspx">hotfixes</category></item><item><title>Announcement: Configuration Manager Documentation Library Update for June 2009</title><link>http://blogs.technet.com/configmgrteam/archive/2009/06/18/announcement-configuration-manager-documentation-library-update-for-june-2009.aspx</link><pubDate>Fri, 19 Jun 2009 01:01:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3256440</guid><dc:creator>Configuration Manager Team</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.technet.com/configmgrteam/comments/3256440.aspx</comments><wfw:commentRss>http://blogs.technet.com/configmgrteam/commentrss.aspx?PostID=3256440</wfw:commentRss><wfw:comment>http://blogs.technet.com/configmgrteam/rsscomments.aspx?PostID=3256440</wfw:comment><description>&lt;P&gt;&lt;EM&gt;[Today's Post is provided by &lt;A href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx"&gt;the Configuration Manager Writing Team&lt;/A&gt;]&lt;/EM&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;The Configuration Manager documentation library (&lt;A href="http://technet.microsoft.com/en-us/library/bb680651.aspx"&gt;http://technet.microsoft.com/en-us/library/bb680651.aspx&lt;/A&gt;) has been updated on the Web and the following information lists the topics that are new or contain significant changes since the April 2009 update. &amp;nbsp;The latest content that has been updated on the Web has &lt;B&gt;Updated: June 1, 2009&lt;/B&gt; at the top of the topic.&lt;/P&gt;
&lt;P mce_keep="true"&gt;In particular, you might want to check out the revised supported configurations, which now include support statements for SQL Server 2008 SP1, Windows Vista, Windows Server 2008 Service Pack 2, and Windows Server 2003 Service Pack 2. &amp;nbsp;Be sure to check out the details for the environments in which these are supported and whether any hotfixes are required:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc161860.aspx"&gt;Configuration Manager 2007 Supported Configurations&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc161823.aspx"&gt;Configuration Manager 2007 SP1 Supported Configurations&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P mce_keep="true"&gt;We also have some new topics for the Configuration Manager 2007 SP2 features and changes, but because SP2 is still in beta, they are not published to the Web with this round of publishing updates.&amp;nbsp; Instead, download the help file from the Connect site, and then search for the topic "What's New in Configuration Manager 2007 SP2".&amp;nbsp; &lt;/P&gt;
&lt;P mce_keep="true"&gt;We do value customer feedback and try to incorporate it when possible. &amp;nbsp;Although we can't promise to make the docs perfect for everybody, we are committed to continual improvement. So, keep that feedback coming, and feel free to contact us about anything related to the documentation by using our usual address of &lt;A href="mailto:SMSDocs@Microsoft.com"&gt;SMSDocs@Microsoft.com&lt;/A&gt;.&amp;nbsp; &lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;What's New in the Configuration Manager Documentation Library for June 2009&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;The following information lists the topics that are new or contain significant changes since the Aril 2009 update:&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb693755.aspx"&gt;Overview of Internet-Based Client Management&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated to include task sequences as one of the features that are not supported when clients are managed on the Internet.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc431360.aspx"&gt;Out of Band Management Console Issues&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- This topic now includes a note at the top that references the &lt;A href="http://go.microsoft.com/fwlink/?LinkId=132001"&gt;Intel vPro Expert Center: Microsoft vPro Manageability Web site&lt;/A&gt;, which should be checked for issues that are specific to AMT (such as behavior differences between firmware versions, how to install and configure the Intel translator, and how to configure AMT).&amp;nbsp; This topic has also been updated to include the known issue of trying to run the out of band management console on Windows XP SP2 and Windows Server SP1.&amp;nbsp; &lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb680540.aspx"&gt;How to Enable or Disable Certificate Revocation Checking (CRL) on Clients&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Updated to clarify that client functions that run as a result of task sequence actions always check the CRL in a native mode site, even after following the procedures to disable CRL checking on clients.&amp;nbsp; This limitation will no longer apply in Configuration Manager 2007 SP2.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb632618.aspx"&gt;Ports Used by Configuration Manager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Clarified that the configurable port TCP 9971 for the AMT management controller to the out of band service is used only for out of band provisioning, and is not used with in-band provisioning.&amp;nbsp; If you are using out of band provisioning, and the server running the out of band service point has the Windows firewall enabled, ensure that this port is allowed.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb680830.aspx"&gt;How to Create a Fallback Status Point in Configuration Manager&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Revised with clarifications such as the inclusion of security best practices for production networks; a reference to installing IIS for Windows Server 2008; which log files to check for successful installation; and how to install the fallback status on a new server.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc678418.aspx"&gt;Troubleshooting SQL Reporting Services Issues&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;- Corrections made to the troubleshooting item "Cannot run reports from the Configuration Manager console".&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb693646.aspx"&gt;Delete Inactive Client Discovery Data Task Overview&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Removed incorrect references to the SMS 2003 Client Health Tool and replaced these with references to Client Status Reporting in Configuration Manager 2007 R2.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb680546.aspx"&gt;How to Remediate Non-Compliant Computers Using Software Distribution&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- Revised so that the query works with multiple versions of SQL Server.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb680398.aspx"&gt;About the Network Access Account&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;- With the help of community content feedback, we realized that this topic was missing a link with instructions how to configure this account.&amp;nbsp; This reference has now been added.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-- &lt;A href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/configuration-manager-writing-team.aspx"&gt;The Configuration Manager Writing Team&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;This posting is provided "AS IS" with no warranties and confers no rights.&lt;/I&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3256440" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/configmgrteam/archive/tags/Documentation/default.aspx">Documentation</category></item><item><title>Announcement:  Configuration Manager 2007 Service Pack 2 Public Beta</title><link>http://blogs.technet.com/configmgrteam/archive/2009/06/17/announcement-configuration-manager-2007-service-pack-2-public-beta.aspx</link><pubDate>Wed, 17 Jun 2009 23:04:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3255966</guid><dc:creator>Configuration Manager Team</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.technet.com/configmgrteam/comments/3255966.aspx</comments><wfw:commentRss>http://blogs.technet.com/configmgrteam/commentrss.aspx?PostID=3255966</wfw:commentRss><wfw:comment>http://blogs.technet.com/configmgrteam/rsscomments.aspx?PostID=3255966</wfw:comment><description>&lt;P&gt;&lt;I&gt;[Today's post is provided by &lt;/I&gt;&lt;A href="http://blogs.technet.com/configmgrteam/pages/michael-cureton-s-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/michael-cureton-s-bio.aspx"&gt;&lt;I&gt;Michael Cureton&lt;/I&gt;&lt;/A&gt;&lt;I&gt;]&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;The System Center Configuration Manager team would like to announce the release of the public beta for Configuration Manager Service Pack 2.&amp;nbsp; This beta is now available for download for all customers.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Service Pack 2 for Configuration Manager 2007 delivers new platform support for Windows 7 client, Windows Vista SP2, Windows Server 2008 R2 and Windows Server 2008 SP2.&amp;nbsp; In addition, Service Pack 2 delivers continued innovation with Intel vPro technology, support for Branch Cache enabled environments, and continued development for 64 bit architectures.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;You can access more information and download the beta by registering for the Configuration Manager 2007 Service Pack 2 Open Beta Program on Connect at &lt;A href="https://connect.microsoft.com/InvitationUse.aspx?ProgramID=3005&amp;amp;InvitationID=%20CM72-HDRW-G3V6&amp;amp;SiteID=16" mce_href="https://connect.microsoft.com/InvitationUse.aspx?ProgramID=3005&amp;amp;InvitationID=%20CM72-HDRW-G3V6&amp;amp;SiteID=16"&gt;https://connect.microsoft.com/InvitationUse.aspx?ProgramID=3005&amp;amp;InvitationID=%20CM72-HDRW-G3V6&amp;amp;SiteID=16&lt;/A&gt;. It can also be found in the Connection Directory sorting by "Connection Name" and is listed under System Center Configuration Manager 2007.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;B&gt;What's New?&lt;/B&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;B&gt;New Operating System Support &lt;/B&gt;&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI&gt;Windows 7 &lt;/LI&gt;
&lt;LI&gt;Windows Vista Sp2&lt;/LI&gt;
&lt;LI&gt;Windows Server 2008 R2 &lt;/LI&gt;
&lt;LI&gt;Windows Server 2008 SP2 &lt;/LI&gt;&lt;/UL&gt;
&lt;P mce_keep="true"&gt;&lt;B&gt;New Features in Out of Band Management&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Configuration Manager 2007 Service Pack 2 improves on the Intel AMT integration provided in Service Pack 1.&amp;nbsp; SP2 adds full feature support for computers that have the Intel vPro chip set and AMT firmware versions 4 &amp;amp; 5.&amp;nbsp; In addition to providing feature parity with SP1 and AMT firmware versions 3.2.1, 4.0 and 5.0, the following new features are supported: &lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI&gt;Wireless management with up to 8 wireless profiles (mobile ONLY)&lt;/LI&gt;
&lt;LI&gt;End point access control: 802.1x support&lt;/LI&gt;
&lt;LI&gt;Audit logging&lt;/LI&gt;
&lt;LI&gt;Power policy extensions&lt;/LI&gt;
&lt;LI&gt;Data storage&lt;/LI&gt;&lt;/UL&gt;
&lt;P mce_keep="true"&gt;&lt;B&gt;Asset Intelligence Certificate Requirement Removal&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Configuration Manager Service Pack 1 introduced Asset Intelligence v1.5.&amp;nbsp; This version allowed customers to configure an online synchronization to ensure that their catalog was up to date with the latest Microsoft inventory for both hardware and applications.&amp;nbsp; This initial release required a certificate.&amp;nbsp; With Service Pack 2, the requirement to have the certificate has been removed, so any customer can configure their Asset Intelligence capabilities to connect online and update their catalog.&amp;nbsp; Software Assurance is not required for this functionality.&amp;nbsp; &lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;B&gt;64-bit Architecture Development&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;Service Pack 2 will also continue to deliver new support for x64 architectures, including the following:&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI&gt;X64 support for Operations Manager 2007 Client Agent &lt;/LI&gt;
&lt;LI&gt;Update to Management Packs for 64-bit operating systems - SP2 will ship 64-bit performance counters (the management pack is a separate release)&lt;/LI&gt;
&lt;LI&gt;Remote control support added for x64 XP &amp;nbsp;and x64 Server 2003&lt;/LI&gt;&lt;/UL&gt;
&lt;P mce_keep="true"&gt;&lt;B&gt;Improved Client Policy Evaluation&lt;/B&gt;&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI&gt;Faster policy processing&lt;/LI&gt;
&lt;LI&gt;More efficient software distribution configured to run at user logon&lt;/LI&gt;&lt;/UL&gt;
&lt;P mce_keep="true"&gt;&lt;B&gt;Branch Cache Support&lt;/B&gt;&lt;/P&gt;
&lt;UL type=disc&gt;
&lt;LI&gt;Support for scenarios where Windows Server 2008 R2 and Windows 7 Client are present and Branch Cache is enabled&lt;/LI&gt;&lt;/UL&gt;
&lt;P mce_keep="true"&gt;We invite you to register for the Configuration Manager 2007 Service Pack 2 Open Beta Program on Connect at &lt;A href="https://connect.microsoft.com/InvitationUse.aspx?ProgramID=3005&amp;amp;InvitationID=%20CM72-HDRW-G3V6&amp;amp;SiteID=16" mce_href="https://connect.microsoft.com/InvitationUse.aspx?ProgramID=3005&amp;amp;InvitationID=%20CM72-HDRW-G3V6&amp;amp;SiteID=16"&gt;https://connect.microsoft.com/InvitationUse.aspx?ProgramID=3005&amp;amp;InvitationID=%20CM72-HDRW-G3V6&amp;amp;SiteID=16&lt;/A&gt;.&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;--&lt;A href="http://blogs.technet.com/configmgrteam/pages/michael-cureton-s-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/michael-cureton-s-bio.aspx"&gt;Michael Cureton&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;This posting is provided "AS IS" with no warranties and confers no rights.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3255966" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/configmgrteam/archive/tags/SP2/default.aspx">SP2</category></item><item><title>Recommendations for PKI Key Lengths and Validity Periods with Configuration Manager</title><link>http://blogs.technet.com/configmgrteam/archive/2009/06/12/recommendations-for-pki-key-lengths-and-validity-periods-with-configuration-manager.aspx</link><pubDate>Fri, 12 Jun 2009 20:29:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3254137</guid><dc:creator>Configuration Manager Team</dc:creator><slash:comments>6</slash:comments><comments>http://blogs.technet.com/configmgrteam/comments/3254137.aspx</comments><wfw:commentRss>http://blogs.technet.com/configmgrteam/commentrss.aspx?PostID=3254137</wfw:commentRss><wfw:comment>http://blogs.technet.com/configmgrteam/rsscomments.aspx?PostID=3254137</wfw:comment><description>&lt;P&gt;&lt;I&gt;[Today's post is provided by &lt;A href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx"&gt;Carol Bailey&lt;/A&gt;]&lt;/I&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;I sometimes get questions from customers about values to set for the key sizes and validity periods for the certificates required for native mode and out of band management in Configuration Manager.&amp;nbsp; This has been a tough one for me to answer, because in the main, these values are external to Configuration Manager and they are PKI design questions with advantages and disadvantages for different values.&amp;nbsp; The higher the key size, the more secure the certificate is from attackers, but will require more processing to use.&amp;nbsp; The longer the validity period, the less certificate maintenance required (and potentially some service disruption), but the certificate is more vulnerable to being compromised.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P mce_keep="true"&gt;Disclaimer:&amp;nbsp; The PKI-related information in this post is external to Configuration Manager, so you will not find this information in the Configuration Manager product documentation.&amp;nbsp; However, we realize that PKI is often new to Configuration Manager admins, and aim to share our knowledge and experience to help you be more successful with the product.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P mce_keep="true"&gt;Until recently, the best advice I could offer customers without their own PKI consultants, was to follow the example of Microsoft default values on certificate templates that closely matched their own certificates. &amp;nbsp;Then check any certificate requirements in our documentation (for example, some certificates have a maximum supported key size), and take into account any overheads associated with renewal. &amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;However, at MMS in Vegas this year, Chris Adams and Ben Shy from Microsoft presented an excellent breakout session that shared their experience about how they implemented native mode and Internet-based client management in Microsoft. &amp;nbsp;This session was called "Demystifying Native Mode Security to Deliver Internet-based Client Management" and one slide I was particularly keen that they shared with customers was their strategy for deciding the key size and validity period.&amp;nbsp; Their numbers are based on &lt;A href="http://www.rsa.com/rsalabs/node.asp?id=2964"&gt;RSA research&lt;/A&gt; and how long it would take an attacker to compromise a certificate.&amp;nbsp; So the higher the key size, the more secure the certificate is (but remember that this comes at the cost of extra processing). Their simple matrix that they presented at MMS looked like this:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV mce_keep="true"&gt;Key length of 1024:&amp;nbsp; Validity period = not greater than 6-12 months&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV mce_keep="true"&gt;Key length of 2048:&amp;nbsp; Validity period = not greater than 2 years&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;Key length of 4096:&amp;nbsp; Validity period = not greater than 16 years&lt;/LI&gt;&lt;/UL&gt;
&lt;P mce_keep="true"&gt;When you are deciding which values to use, we've already noted that you need to take into account any other restrictions - such as maximum supported key size by the application that uses the certificate.&amp;nbsp; However, you also need to take into account what your CA hierarchy can support. A CA cannot issue a certificate with a longer validity period than its own certificate.&amp;nbsp; This one is easy to remember, however, there's also a ticking time limit because a CA cannot issue certificates with a validity period that is longer than its own remaining validity period. &lt;/P&gt;
&lt;P mce_keep="true"&gt;This means that ideally, you want to plan your validity periods very carefully when designing your PKI - taking into account factors such as the type of certificates that you want to use, the applications that will use them, your company's tolerance to&amp;nbsp;security risks, and your renewal strategy.&amp;nbsp; However, in practice, you might have to fit your validity periods around your existing PKI design. &amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;Some examples:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If you want to use a validity period of 10 years for your site server signing certificate, this will not be possible if your issuing CA has a certificate with a validity period of 5 years.&lt;/LI&gt;
&lt;LI&gt;If your issuing CA has a validity period of 5 years but has been up and running for 2 years, it will not be able to deploy certificates with a validity period of 4 years - until its own certificate is renewed.&lt;/LI&gt;&lt;/UL&gt;
&lt;P mce_keep="true"&gt;More information:&lt;/P&gt;
&lt;P mce_keep="true"&gt;For MMS customers who couldn't attend the session in person, unfortunately a recording of the session is not available but you can view the slide deck.&amp;nbsp; Search the MMS catalog by code (SY23) or keyword "Internet-based".&lt;/P&gt;
&lt;P mce_keep="true"&gt;There are numerous articles that help to explain how validity periods are used and configured, but I found this one to be a very useful starting point: &lt;A href="http://technet.microsoft.com/en-us/library/cc740209(WS.10).aspx"&gt;Renewing a certification authority&lt;/A&gt;.&lt;/P&gt;
&lt;P mce_keep="true"&gt;For any key size limitations applicable to the certificates used in native mode and out of band management:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://technet.microsoft.com/en-us/library/bb680733.aspx"&gt;Certificate Requirements for Native Mode&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc161874.aspx"&gt;Certificate Requirements for Out of Band Management&lt;/A&gt; &lt;/LI&gt;&lt;/UL&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;--&lt;A href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx" mce_href="http://blogs.technet.com/configmgrteam/pages/carol-bailey-s-bio.aspx"&gt;Carol Bailey&lt;/A&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;I&gt;This posting is provided "AS IS" with no warranties, and confers no rights.&lt;/I&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3254137" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/configmgrteam/archive/tags/Certificates/default.aspx">Certificates</category><category domain="http://blogs.technet.com/configmgrteam/archive/tags/PKI/default.aspx">PKI</category><category domain="http://blogs.technet.com/configmgrteam/archive/tags/CA/default.aspx">CA</category></item></channel></rss>