question

MichaelFleet-9193 avatar image
0 Votes"
MichaelFleet-9193 asked ·

Windows 7 x86 to Windows 10 x64 Remote Migration

Good afternoon,

In advance of a future transition to Microsoft Intune we're refreshing our devices from Windows 7 x86 to Windows 10 x64 using an SCCM task sequence and usually we would do this on the LAN or by standalone media. We're currently running SCCM 1802 and Windows 10 1803. We have no plans to upgrade SCCM given the impending move to Intune and therefore (due to compatibility) will not be upgrading Windows 10 to a later release on this platform (we plan to push the latest version of Windows 10 from Intune).

A large proportion of our devices are now remotely connecting to our LAN over VPN (zScaler). Although I can push the refresh task sequence from SCCM I'm wondering how I could still establish a VPN connection during the build so the machine will join the Domain, setup BitLocker encryption and install the remainder of applications from SCCM.

I want to avoid sending an engineer to every site. Any suggestions please?

Michael

windows-10-generalwindows-7-general
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

DaleKudusi-MSFT avatar image
0 Votes"
DaleKudusi-MSFT answered ·

Hi
You could check out the Always On VPN feature:
https://docs.microsoft.com/en-us/windows-server/remote/remote-access/vpn/vpn-map-da
In this scenario, you cloud try these solutions on this link:
https://www.imab.dk/deploying-software-updates-via-vpn-cloud-management-gateway-and-microsoft-update-using-configuration-manager/

Please note: Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.

I hope this information above can help you.
Please feel free to let us know if you need further assistance.

· 6 ·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,

Thanks for your comment.

I really want to avoid using another VPN solution given we have already made an investment in zScaler however I have now considered we could use our legacy IPsec VPN - Cisco AnyConnect. This is installed during the Task Sequence and I'm thinking it may be possible to invoke the VPN using a Command Line statement. Any idea if this will work?

From what I understand it's not possible to refresh the OS from the Cloud Management Gateway. Is this correct?

Thanks again,

Michael

0 Votes 0 ·

Hi
Sorry for the late response.
Cloud Management Gateway can do application deployment, patch deployment, OS upgrade (but not full OSD deployment).
Issues related to Cisco Anyconnect might need to check out Cisco Support.

Please note: Information posted in the given link is hosted by a third party.
Microsoft does not guarantee the accuracy and effectiveness of information

Best regards.



1 Vote 1 ·

Thanks for coming back to me.

On a related note, is it possible to cache OSD content locally on a partition which does not get formatted during the SCCM task sequence? This will go some way towards a solution.

0 Votes 0 ·
Show more comments

Unfortunately a full operating system deployment (OSD) is not supported with CMG.

0 Votes 0 ·