Trouble installing SCCM Client on Workgroup system using bulk enrollment token

Dean 1 Reputation point
2021-03-03T20:49:39.987+00:00

I am trying to experiment with the bulk enrollment feature of our SCCM Version 2010 environment. I have created the bulk enrollment token, and copied it to my installation USB drive. The CCMSetup.log shows CCM_E_NO_TOKEN_AUTH, followed by a DownloadFilebyWinHTTP error 0x87d00455. I would like to validate the Token is actually being used, and is being recognized at the CMG. I have an internally generated cert manageing the traffic between my CMG, and the connection point on-prem, My intention is to use eHTTP for client communication, but this system isn't AD, or AAD joined (yet). Can anyone offer any advice where to begin looking? TY!

Microsoft Configuration Manager
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Jason Sandys 31,151 Reputation points Microsoft Employee
    2021-03-04T00:56:49.433+00:00

    Does the client device trust the PKI that issued the cert used for the CMG?


  2. Dean 1 Reputation point
    2021-03-04T15:04:11.513+00:00

    Hi Jason, No the client is an out-of-the box system fresh off the shelf. I thought the token was the authentication key, to bypass any on-prem/AD cert requirements. I was expecting to deliver the client, then a VPN client, and then perform an AD join, and move the client into a fully managed state. We are not co-managing at this point, (hopefully soon) but this was "my" way to leverage the CMG for those new systems. Thanks