<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The Mobile Device Manager Support Team Blog : SP1</title><link>http://blogs.technet.com/mdm/archive/tags/SP1/default.aspx</link><description>Tags: SP1</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Group Policy setting “Code Word” for System Center Mobile Device Manager 2008 is not correctly applied to Windows Mobile 6.1 mobile devices when the policy is Disabled</title><link>http://blogs.technet.com/mdm/archive/2009/08/13/group-policy-setting-code-word-for-system-center-mobile-device-manager-2008-is-not-correctly-applied-to-windows-mobile-6-1-mobile-devices-when-the-policy-is-disabled.aspx</link><pubDate>Thu, 13 Aug 2009 19:00:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3273162</guid><dc:creator>jchornbe</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mdm/comments/3273162.aspx</comments><wfw:commentRss>http://blogs.technet.com/mdm/commentrss.aspx?PostID=3273162</wfw:commentRss><description>&lt;p&gt;&lt;img title="image" border="0" alt="image" align="left" src="http://blogs.technet.com/blogfiles/mdm/WindowsLiveWriter/SystemCenterMobileDeviceManagersupportfo_9A3A/image_3.png" width="76" height="73" /&gt;When you disable the Group Policy setting &lt;em&gt;Code Word&lt;/em&gt; by using Microsoft System Center Mobile Device Manager (MDM) 2008 Group Policy management functionality, some Windows Mobile 6.1 mobile devices may continue to use the previously set code word.&lt;/p&gt;  &lt;p&gt;This group policy setting affects this Windows Mobile registry key when applied to the device:&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;HKEY_LOCAL_MACHINE\Comm\Security\LASSD\CodeWord&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;When this policy is set to Enable the Code Word value is set in this registry key, however when this policy is set to Disable the registry key is deleted. When the registry key is not found, the Windows Mobile device continues to use whatever code word was set previously.&lt;/p&gt;  &lt;p&gt;Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the &amp;quot;Applies to&amp;quot; section. This problem has not been corrected at the time of publication of this article.&lt;/p&gt;  &lt;p&gt;The only workaround at this time is to not disable the policy. Using the Group Policy Management Console, rather than set the policy to Disable, always set it to Enable and specify your desired code word.&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Note: Special thanks to our very own Dave Hattaway for contributing the preceding information.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;J.C. Hornbeck | Manageability Knowledge Engineer&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3273162" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mdm/archive/tags/Troubleshoot/default.aspx">Troubleshoot</category><category domain="http://blogs.technet.com/mdm/archive/tags/SP1/default.aspx">SP1</category><category domain="http://blogs.technet.com/mdm/archive/tags/Policy/default.aspx">Policy</category><category domain="http://blogs.technet.com/mdm/archive/tags/CodeWord/default.aspx">CodeWord</category></item><item><title>The Group Policy setting “Code word frequency” for System Center Mobile Device Manager 2008 is not correctly applied to Windows Mobile 6.1 mobile devices when the policy is “Disabled”</title><link>http://blogs.technet.com/mdm/archive/2009/08/12/the-group-policy-setting-code-word-frequency-for-system-center-mobile-device-manager-2008-is-not-correctly-applied-to-windows-mobile-6-1-mobile-devices-when-the-policy-is-disabled.aspx</link><pubDate>Wed, 12 Aug 2009 20:03:47 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3272820</guid><dc:creator>jchornbe</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mdm/comments/3272820.aspx</comments><wfw:commentRss>http://blogs.technet.com/mdm/commentrss.aspx?PostID=3272820</wfw:commentRss><description>&lt;p&gt;&lt;img title="image" border="0" alt="image" align="left" src="http://blogs.technet.com/blogfiles/mdm/WindowsLiveWriter/SystemCenterMobileDeviceManagersupportfo_9A3A/image_3.png" width="76" height="73" /&gt;When you disable the Group Policy setting &lt;strong&gt;Code word frequency&lt;/strong&gt; by using Microsoft System Center Mobile Device Manger (MDM) 2008 Group Policy management functionality, some Windows Mobile 6.1 mobile devices may continue to ask the user to enter a code word after a number of incorrect password attempts.&lt;/p&gt;  &lt;p&gt;This group policy setting affects this Windows Mobile registry key when applied to the device:&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;HKEY_LOCAL_MACHINE\Comm\Security\LASSD\CodeWordFrequency&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;When this policy is set to Enable the frequency value is set in this registry key, however when this policy is set to Disable the registry key is deleted.&amp;#160; When the registry key is not found, the Windows Mobile device reverts to the default behavior, which is to ask the user to enter a codeword after 8 incorrect password attempts.&lt;/p&gt;  &lt;p&gt;This issue is fixed in System Center Mobile Device Manager 2008 Service Pack 1 but the following workaround is also available:&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Important: The following workaround applies only to the English version of Microsoft System Center Mobile Device Manger 2008. There are no workarounds for other language versions of the product at this time.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Warning: Serious problems might occur if you modify system files incorrectly. These problems might require that you reinstall server software or components of server software. Microsoft cannot guarantee that these problems can be solved. Modify the system files at your own risk.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Important: The following workaround requires you to modify an important system file. Make sure that you back up the referenced file before you modify it. Make sure that you know how to restore the system file if a problem occurs. Do not proceed with the following procedure if you do not know how to back up and restore a file. Revert to the original file if you encounter any problems with the workaround.&lt;/em&gt; &lt;/p&gt;  &lt;p&gt;The following steps modify the ADM template file that includes the Code word frequency Group Policy setting. When you have successfully modified the file, you can use the Code word frequency Group Policy setting to correctly update managed devices.&lt;/p&gt;  &lt;p&gt;1.&amp;#160;&amp;#160;&amp;#160; On the computer on which you have installed the MDM Administrator Tools, navigate to the %windir%\INF folder.&lt;/p&gt;  &lt;p&gt;2.&amp;#160;&amp;#160;&amp;#160; Type the following at a command prompt to make a backup copy of the mobile.adm file:&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;copy mobile.adm mobile.adm.bak&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;3.&amp;#160;&amp;#160;&amp;#160; In a text editor, such as Notepad, edit the mobile.adm file to change the MIN setting for Policy_CodeWordFrequency &lt;/p&gt;  &lt;p&gt;REPLACE: &lt;/p&gt;  &lt;p&gt;&lt;font color="#004080"&gt;&lt;em&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; POLICY !!Policy_CodeWordFrequency        &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; EXPLAIN !!Explain_CodeWordFrequency         &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; PART !!Part_CodeWordFrequency NUMERIC        &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; KEYNAME &amp;quot;SOFTWARE\Policies\Microsoft\Windows Mobile Settings\Registry\HKLM\Comm\Security\Policy\LASSD&amp;quot;        &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; VALUENAME &amp;quot;CodewordFrequency&amp;quot;        &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; MIN 1        &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; MAX 4294967295        &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; DEFAULT 8        &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; END PART        &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; END POLICY ;;!!Policy_CodeWordFrequency&lt;/em&gt;&lt;/font&gt; &lt;/p&gt;  &lt;p&gt;WITH: &lt;/p&gt;  &lt;p&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;font color="#004080"&gt;POLICY !!Policy_CodeWordFrequency      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; EXPLAIN !!Explain_CodeWordFrequency       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; PART !!Part_CodeWordFrequency NUMERIC      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; KEYNAME &amp;quot;SOFTWARE\Policies\Microsoft\Windows Mobile Settings\Registry\HKLM\Comm\Security\Policy\LASSD&amp;quot;      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; VALUENAME &amp;quot;CodewordFrequency&amp;quot;      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; MIN 0      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; MAX 4294967295      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; DEFAULT 8      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; END PART      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160; END POLICY ;;!!Policy_CodeWordFrequency &lt;/font&gt;&lt;/p&gt;  &lt;p&gt;4.&amp;#160;&amp;#160;&amp;#160; Save the file and exit the text editor.&lt;/p&gt;  &lt;p&gt;5.&amp;#160;&amp;#160;&amp;#160; Using the Group Policy Management Console, instead of setting this policy to Disable, set it to Enable and set the value to 0. &lt;/p&gt;  &lt;p&gt;To apply the new setting to managed devices, you must update the Code word frequency Group Policy setting in MDM. To refresh the setting in MDM, in MDM Console, run the following cmdlet: &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;Update-MobilePolicyCalculation &amp;lt;device&amp;gt;&lt;/em&gt;&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;Where &amp;lt;device&amp;gt; is the managed device on which you want to update the Group Policy setting. New settings are pushed down to managed devices during the next synchronization with MDM.&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Note: Special thanks to our very own Dave Hattaway for contributing the preceding information.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;J.C. Hornbeck | Manageability Knowledge Engineer&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3272820" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mdm/archive/tags/Troubleshoot/default.aspx">Troubleshoot</category><category domain="http://blogs.technet.com/mdm/archive/tags/SP1/default.aspx">SP1</category><category domain="http://blogs.technet.com/mdm/archive/tags/Code+Word+Frequency/default.aspx">Code Word Frequency</category><category domain="http://blogs.technet.com/mdm/archive/tags/Policy/default.aspx">Policy</category></item><item><title>SCMDM SP1 Support for Virtualization</title><link>http://blogs.technet.com/mdm/archive/2009/05/28/scmdm-sp1-support-for-virtualization.aspx</link><pubDate>Thu, 28 May 2009 09:57:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3246674</guid><dc:creator>Rob Davies</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mdm/comments/3246674.aspx</comments><wfw:commentRss>http://blogs.technet.com/mdm/commentrss.aspx?PostID=3246674</wfw:commentRss><description>&lt;P&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; MARGIN-LEFT: 0px; BORDER-LEFT-WIDTH: 0px; MARGIN-RIGHT: 0px" title=image border=0 alt=image align=left src="http://blogs.technet.com/blogfiles/mdm/WindowsLiveWriter/SystemCenterMobileDeviceManagersupportfo_9A3A/image_3.png" width=76 height=73 mce_src="http://blogs.technet.com/blogfiles/mdm/WindowsLiveWriter/SystemCenterMobileDeviceManagersupportfo_9A3A/image_3.png"&gt;As you may know, with the Service Pack 1 release of SCMDM we introduced support for virtualization of our server roles.&amp;nbsp; This allows you to run the Windows Server 2003 x64 guest OS in a Hyper-V environment.&amp;nbsp; We wanted to clarify that this applies to the virtualization of the Device Management and Enrollment Server SCMDM roles, but does not apply to the Gateway Server role.&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-ansi-language: EN-US" lang=EN-US&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;The architecture of the Gateway server requires two network cards, one for the internet and one for the internal network, which the SCMDM VPN monitors traffic on.&amp;nbsp; We recommend that this should not be implemented on a virtual machine due to the complications that this introduces.&amp;nbsp; Therefore the supported setup is to use a physical server with 2 network interfaces for your SCMDM Gateway Servers.&amp;nbsp; For more information about the Gateway Server role and its requirements, please see &lt;A href="http://technet.microsoft.com/en-us/library/dd252779.aspx" target=_blank mce_href="http://technet.microsoft.com/en-us/library/dd252779.aspx"&gt;http://technet.microsoft.com/en-us/library/dd252779.aspx&lt;/A&gt;.&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0cm 0cm 0pt" class=MsoNormal&gt;&lt;STRONG&gt;Rob Davies | Senior Support Engineer&lt;/STRONG&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3246674" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mdm/archive/tags/Troubleshoot/default.aspx">Troubleshoot</category><category domain="http://blogs.technet.com/mdm/archive/tags/Setup/default.aspx">Setup</category><category domain="http://blogs.technet.com/mdm/archive/tags/SP1/default.aspx">SP1</category><category domain="http://blogs.technet.com/mdm/archive/tags/Virtualization/default.aspx">Virtualization</category></item><item><title>System Center Mobile Device Manager support for Windows Server 2008 Certificate Authority</title><link>http://blogs.technet.com/mdm/archive/2009/05/18/system-center-mobile-device-manager-support-for-windows-server-2008-certificate-authority.aspx</link><pubDate>Mon, 18 May 2009 19:03:47 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3242885</guid><dc:creator>jchornbe</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mdm/comments/3242885.aspx</comments><wfw:commentRss>http://blogs.technet.com/mdm/commentrss.aspx?PostID=3242885</wfw:commentRss><description>&lt;p&gt;&lt;a href="http://technet.microsoft.com/en-us/scmdm/default.aspx" target="_blank"&gt;&lt;img title="image" style="border-right: 0px; border-top: 0px; display: inline; margin-left: 0px; border-left: 0px; margin-right: 0px; border-bottom: 0px" height="73" alt="image" src="http://blogs.technet.com/blogfiles/mdm/WindowsLiveWriter/SystemCenterMobileDeviceManagersupportfo_9A3A/image_3.png" width="76" align="left" border="0" /&gt;&lt;/a&gt; We are happy to announce that we now support System Center Mobile Device Manager 2008 SP1 with a Windows Server 2008 Enterprise Edition Certificate Authority.&amp;#160; We’ll be documenting this on TechNet in the near future but we wanted to let you all know that this is now fully tested and supported.&lt;/p&gt;  &lt;p&gt;For this to work on the device side, we require Windows Mobile build 6.1.4 or later.&amp;#160; For earlier Windows Mobile 6.1 builds, you can install update KB951840 from &lt;a href="http://support.microsoft.com/kb/951840/"&gt;http://support.microsoft.com/kb/951840/&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;So now you can deploy SCMDM with a Windows Server 2008 issuing CA in a Server 2008 functional level domain.&amp;#160; For the complete list of system requirements for SCMDM please see &lt;a href="http://technet.microsoft.com/en-gb/library/dd261866.aspx"&gt;http://technet.microsoft.com/en-gb/library/dd261866.aspx&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Rob Davies | Senior Support Engineer&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3242885" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mdm/archive/tags/Troubleshoot/default.aspx">Troubleshoot</category><category domain="http://blogs.technet.com/mdm/archive/tags/SP1/default.aspx">SP1</category><category domain="http://blogs.technet.com/mdm/archive/tags/Certificates/default.aspx">Certificates</category><category domain="http://blogs.technet.com/mdm/archive/tags/Windows+Server+2008/default.aspx">Windows Server 2008</category></item><item><title>Collecting large amount of device inventory information during OMA session causes MDM server to timeout</title><link>http://blogs.technet.com/mdm/archive/2009/01/08/collecting-large-amount-of-device-inventory-information-during-oma-session-causes-mdm-server-to-timeout.aspx</link><pubDate>Thu, 08 Jan 2009 16:38:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3178140</guid><dc:creator>jchornbe</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mdm/comments/3178140.aspx</comments><wfw:commentRss>http://blogs.technet.com/mdm/commentrss.aspx?PostID=3178140</wfw:commentRss><description>&lt;p&gt;Here's an issue we run into every now and then so I thought it might be worth a mention here.&amp;#160; If you're noticing GP and software distribution delivery failures then this may be your issue:&lt;/p&gt;  &lt;p&gt;========&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Issue:&lt;/u&gt;&lt;/strong&gt; Collecting large amount of device inventory information during an Open Mobile Alliance (OMA) session may cause the System Center Mobile Device Manager server to timeout. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Cause:&lt;/u&gt;&lt;/strong&gt; During the first OMA session on some devices, if the device is instructed by the server to collect a large amount of inventory information it might result in the session taking up to 20 minutes to complete or it may timeout completely depending on the timeout settings on the server. This delay results from the time taken by the device to retrieve and process inventory information that the server requested.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Resolution: &lt;/u&gt;&lt;/strong&gt;To resolve this problem, restore the default inventory collection set using the &lt;strong&gt;&lt;em&gt;Restore-MDMInventoryDefaults&lt;/em&gt;&lt;/strong&gt; cmdlet or remove items from the inventory collection using &lt;strong&gt;&lt;em&gt;Set-MDMInventoryItem&lt;/em&gt;&lt;/strong&gt; cmdlet. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Additional Information:&lt;/u&gt;&lt;/strong&gt; In this scenario the device user will notice Group Policy and software distribution delivery failure.&amp;#160; The server administrator may also notice two messages in system logs:&lt;/p&gt;  &lt;p&gt;&lt;em&gt;The management session with device xxx (device SID is displayed here not device ID) was not completed. The connection may have been lost, or the session timed out due to inactivity.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;and&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Erroneous OMA DM message received from device xxx&amp;#160; (device SID is displayed here not device ID) during management session.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;========&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;J.C. Hornbeck | Manageability Knowledge Engineer&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3178140" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mdm/archive/tags/Troubleshoot/default.aspx">Troubleshoot</category><category domain="http://blogs.technet.com/mdm/archive/tags/Error/default.aspx">Error</category><category domain="http://blogs.technet.com/mdm/archive/tags/SP1/default.aspx">SP1</category><category domain="http://blogs.technet.com/mdm/archive/tags/CM/default.aspx">CM</category></item><item><title>SCMDM: Enrollment fails with "Unknown error in Enrollment service: System.ArgumentNullException: Value cannot be null"</title><link>http://blogs.technet.com/mdm/archive/2009/01/05/scmdm-enrollment-fails-with-unknown-error-in-enrollment-service-system-argumentnullexception-value-cannot-be-null.aspx</link><pubDate>Mon, 05 Jan 2009 17:29:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3176553</guid><dc:creator>jchornbe</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mdm/comments/3176553.aspx</comments><wfw:commentRss>http://blogs.technet.com/mdm/commentrss.aspx?PostID=3176553</wfw:commentRss><description>&lt;P&gt;Here's another MDM enrollment failure issue we ran across recently that's caused by the CA not being available when the SCMDM Enrollment Service starts.&amp;nbsp; Fortunately the solution to this one is pretty easy:&lt;/P&gt;
&lt;P&gt;========&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Issue:&lt;/U&gt;&lt;/STRONG&gt; Enrollment fails and the following event is logged on the Enrollment Server:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color=#004080&gt;Unknown error in Enrollment service: &lt;BR&gt;System.ArgumentNullException: Value cannot be null. &lt;BR&gt;Parameter name: data &lt;BR&gt;&amp;nbsp;&amp;nbsp; at Microsoft.Mobile.ManagementServices.EnrollmentServer.CryptoService.ComputeHmac(Byte[] data, Byte[] sessionKey) &lt;BR&gt;&amp;nbsp;&amp;nbsp; at Microsoft.Mobile.ManagementServices.EnrollmentServer.Authentication.AuthenticateServer(BootstrappingRequest rc) &lt;BR&gt;&amp;nbsp;&amp;nbsp; at Microsoft.Mobile.ManagementServices.EnrollmentServer.Authentication.Authenticate(RequestContext rc)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Cause:&lt;/U&gt;&lt;/STRONG&gt; This can occur if the Certificate Authority (CA) was not running when the SCMDM Enrollment Service started. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Resolution:&lt;/U&gt;&lt;/STRONG&gt; Restart the SCMDM Enrollment Service. &lt;/P&gt;
&lt;P&gt;========&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;J.C. Hornbeck | Manageability Knowledge Engineer&lt;/STRONG&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3176553" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mdm/archive/tags/Troubleshoot/default.aspx">Troubleshoot</category><category domain="http://blogs.technet.com/mdm/archive/tags/Error/default.aspx">Error</category><category domain="http://blogs.technet.com/mdm/archive/tags/SP1/default.aspx">SP1</category><category domain="http://blogs.technet.com/mdm/archive/tags/CM/default.aspx">CM</category><category domain="http://blogs.technet.com/mdm/archive/tags/Enrollment/default.aspx">Enrollment</category></item><item><title>SCMDM: Mobile Device Manager setup error: "Failed to determine status of MDM databases on SQL instance"</title><link>http://blogs.technet.com/mdm/archive/2008/12/18/scmdm-mobile-device-manager-setup-error-failed-to-determine-status-of-mdm-databases-on-sql-instance.aspx</link><pubDate>Thu, 18 Dec 2008 19:28:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3170873</guid><dc:creator>jchornbe</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mdm/comments/3170873.aspx</comments><wfw:commentRss>http://blogs.technet.com/mdm/commentrss.aspx?PostID=3170873</wfw:commentRss><description>&lt;P&gt;Here's one more MDM Service Pack 1 issue for you, this one involving a setup error you might run into when upgrading:&lt;/P&gt;
&lt;P&gt;========&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Issue:&lt;/U&gt;&lt;/STRONG&gt; Upgrading to System Center Mobile Device Manager 2008 SP1 fails with the following message: &lt;/P&gt;
&lt;P&gt;Failed to determine status of MDM databases on SQL instance '&amp;lt;instance_name&amp;gt;'. Setup will now roll back all changes &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Cause:&lt;/U&gt;&lt;/STRONG&gt; During the upgrade, System Center Mobile Device Manager 2008 SP1 does not have access to the DB_USER and DB_PWD properties provided in previous installations of Device Management Servers or Enrollment Servers. It will instead default to using the current windows user's credentials. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Resolution:&lt;/U&gt;&lt;/STRONG&gt; There are two ways to work around this issue: &lt;/P&gt;
&lt;P&gt;1. Use Windows integrated authentication instead of the SQL username and password. The user who performs the upgrade must have sufficient privileges on the SQL Server where the MDM databases reside. &lt;/P&gt;
&lt;P&gt;or &lt;/P&gt;
&lt;P&gt;2. Uninstall your existing version of MDM prior to installing the SP1 version. Do not remove the existing databases during the uninstall process or your data will be lost. Once MDM is uninstalled, install System Center Mobile Device Manager 2008 SP1. It will give you the option to use the databases from your previous installation of MDM. &lt;/P&gt;
&lt;P&gt;========&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;J.C. Hornbeck | Manageability Knowledge Engineer&lt;/STRONG&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3170873" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mdm/archive/tags/Troubleshoot/default.aspx">Troubleshoot</category><category domain="http://blogs.technet.com/mdm/archive/tags/SP1/default.aspx">SP1</category><category domain="http://blogs.technet.com/mdm/archive/tags/CM/default.aspx">CM</category></item><item><title>SCMDM: Enrollment fails if a port other than 443 is used for the Enrollment Service</title><link>http://blogs.technet.com/mdm/archive/2008/12/17/scmdm-enrollment-fails-if-a-port-other-than-443-is-used-for-the-enrollment-service.aspx</link><pubDate>Wed, 17 Dec 2008 16:45:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3170269</guid><dc:creator>jchornbe</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mdm/comments/3170269.aspx</comments><wfw:commentRss>http://blogs.technet.com/mdm/commentrss.aspx?PostID=3170269</wfw:commentRss><description>&lt;p&gt;Here's another SP1 issue that we came across.&amp;#160; If your server and client logs indicate that Enrollment failed because it could not resolve the Enrollment server URL and you changed the port then this may be your issue:&lt;/p&gt;  &lt;p&gt;========&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Issue:&lt;/u&gt;&lt;/strong&gt; The server and client logs indicate that enrollment failed because it could not resolve the enrollment server URL. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Cause:&lt;/u&gt;&lt;/strong&gt; Enrollment can fail if PAT (Port Address Translation) is used or if an alternate port other than 443 is used for the Enrollment Service. &lt;/p&gt;  &lt;p&gt;Setup itself does not allow you to specify an alternate port number for the enrollment server when it is installed, so if an alternate port is specified in IIS after installation, and the SCP value for the enrollment server is not changed, then client auto discovery breaks. What happens is that the client is sent back a request to switch to the URI of an enrollment server without the alternate port causing the enrollment to fail. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Resolution:&lt;/u&gt;&lt;/strong&gt; If the port number in IIS is changed to a port other than 443, the SCP value must also be changed. &lt;/p&gt;  &lt;p&gt;To change the SCP value follow these steps: &lt;/p&gt;  &lt;p&gt;1. Launch ADSIEDIT.MSC. &lt;/p&gt;  &lt;p&gt;2. Right click on &amp;#8220;CN=Instance&amp;#8221; to bring up the property dialog box. &lt;/p&gt;  &lt;p&gt;3. Check the &amp;#8216;Show only attributes that have values&amp;#8217; checkbox. &lt;/p&gt;  &lt;p&gt;4. Double click on &amp;#8216;keywords&amp;#8217; attribute. &lt;/p&gt;  &lt;p&gt;5. Change the &amp;#8220;enurl= &amp;#8230;&amp;#8221; value to the new port number. &lt;/p&gt;  &lt;p&gt;========&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;J.C. Hornbeck | Manageability Knowledge Engineer&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3170269" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mdm/archive/tags/Troubleshoot/default.aspx">Troubleshoot</category><category domain="http://blogs.technet.com/mdm/archive/tags/SP1/default.aspx">SP1</category><category domain="http://blogs.technet.com/mdm/archive/tags/CM/default.aspx">CM</category><category domain="http://blogs.technet.com/mdm/archive/tags/Enrollment/default.aspx">Enrollment</category></item><item><title>SCMDM: Set-EnrollmentPermissions returns "Error encountered when delegating container..."</title><link>http://blogs.technet.com/mdm/archive/2008/12/16/scmdm-set-enrollmentpermissions-returns-error-encountered-when-delegating-container.aspx</link><pubDate>Tue, 16 Dec 2008 18:51:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3169742</guid><dc:creator>jchornbe</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mdm/comments/3169742.aspx</comments><wfw:commentRss>http://blogs.technet.com/mdm/commentrss.aspx?PostID=3169742</wfw:commentRss><description>&lt;P&gt;Here's another MDM SP1 issue for you.&amp;nbsp; This one involves the &lt;STRONG&gt;Set-EnrollmentPermissions&lt;/STRONG&gt; command and an error you can receive if SCMDMEnrollmentServers has full permissions on the specified OU:&lt;/P&gt;
&lt;P&gt;========&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Issue:&lt;/U&gt;&lt;/STRONG&gt; When running the &lt;STRONG&gt;Set-EnrollmentPermissions&lt;/STRONG&gt; command you may receive the following error: &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color=#004080&gt;Set-EnrollmentPermissions : Error encountered when delegating container "OU=SCMDM Managed Devices (Instance1),DC=yonaloc,DC=nttest,DC=microsoft,DC=com" permission to Enrollment Server. &lt;BR&gt;At line:1 char:26 &lt;BR&gt;+ Set-EnrollmentPermissions&amp;nbsp; &amp;lt;&amp;lt;&amp;lt;&amp;lt; "SCMDM MAnaged Devices (Instance1)"&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Cause:&lt;/U&gt;&lt;/STRONG&gt; The Set-EnrollmentPermissions command verifies what permissions SCMDMEnrollmentServers has on the specified OU (i.e. the OU that is passed in the command).&amp;nbsp; There is a known issue in this verification process where it will return false if Full Permissions are enabled.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Resolution:&lt;/U&gt;&lt;/STRONG&gt; Do not enable full permission for SCMDMEnrollmentServers group on the device OU. To workaround this issue delete the SCMDMEnrollmentServers group from Security.&amp;nbsp; To do this follow these steps:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Run DSA.MSC. &lt;/LI&gt;
&lt;LI&gt;Find the OU where you were trying to set permissions. &lt;/LI&gt;
&lt;LI&gt;Right click on the OU and select Properties. &lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;On the Security tab, click on SCCMEnrollmentServers(&amp;lt;your instance name&amp;gt;) and remove it.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;The last step is to run the Set-EnrollmentPermissions command again.&amp;nbsp; This time it should succeed without error.&lt;/P&gt;
&lt;P&gt;========&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;J.C. Hornbeck | Manageability Knowledge Engineer&lt;/STRONG&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3169742" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mdm/archive/tags/Error/default.aspx">Error</category><category domain="http://blogs.technet.com/mdm/archive/tags/SP1/default.aspx">SP1</category><category domain="http://blogs.technet.com/mdm/archive/tags/CM/default.aspx">CM</category><category domain="http://blogs.technet.com/mdm/archive/tags/Enrollment/default.aspx">Enrollment</category></item></channel></rss>