question

StewartPollock-0389 avatar image
0 Votes"
StewartPollock-0389 asked StewartPollock-1448 commented

ConfigMgr CMG Classic Cloud Service

Hi

We're about to remove the Central Admin Site from our ConfigMgr 2103 environment. We currently have a single CMG deployed with cloud service classic.

I had been informed here that it should be possible to remove the existing CMG then reinstall at the Primary Site Server using the same CName and certificate and internet clients would just reconnect to the new CMG without us having a requirement for them to be back on the intranet at some point.

I've noticed that the cloud service classic has just been deprecated this month however. What I'd like to know is if this means it won't be possible to reinstall the CMG at the Primary Site via this method. Does anybody know if the deprecation notice now means this isn't possible?

Thanks


mem-cm-general
· 6
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

What I'd like to know is if this means it won't be possible to reinstall the CMG at the Primary Site via this method.

Deprecated doesn't mean not available anymore. The functionality won't be removed until next year so you'll be able to set up a new CMG on the primary site using either the classic cloud service or the VMSS scale set. As long as you used a PKI cert from a public CA, then there's really no difference as you can simply point the CName to the new VMSS name. If you used an internal PKI cert, well then you are stuck and must use a classic CMG for now but you will need to acquire a new cert and deploy a new parallel CMG sometime in the next 9 months or so.

PSA: Using a cert from your internal PKI for your CMG and pointing to cloudapp.net or any domain you don't own is just not a good idea even if it works and is supported.

0 Votes 0 ·

Hi Jason, thanks as always for the comprehensive answer.

It's a public cert so no problem on that front. I had however assumed there was a better chance of successfully switching clients to the new CMG instance at the primary site if it was deployed as classic service in the same fashion as the original. My plan was to then upgrade to 2107 and convert the new CMG to VMSS.

IYou also answered my previous question around this scenario here. You mentioned that it wasn't something you'd tested at the time but saw no reason it wouldn't work. Out of interest, are you aware of anybody having done this successfully since?


0 Votes 0 ·
Jason-MSFT avatar image Jason-MSFT StewartPollock-1448 ·

My plan was to then upgrade to 2107 and convert the new CMG to VMSS.

This will work as well. I don't think there's any advantage to doing this though.

Out of interest, are you aware of anybody having done this successfully since?

Off-hand, no I don't know of any.

0 Votes 0 ·
Show more comments

0 Answers