使用 Configuration Manager 管理 Internet 上的客户端Manage clients on the internet with Configuration Manager

适用范围:Configuration Manager (Current Branch)Applies to: Configuration Manager (current branch)

通常,Configuration Manager 中的多数托管计算机和服务器与执行管理功能的站点系统服务器物理上位于同一内部网络中。Typically in Configuration Manager, most of the managed computers and servers are physically on the same internal network as the site system servers that perform management functions. 但是,当客户端连接到 Internet 时,你可以在内部网络外对其进行管理。However, you can manage clients outside your internal network when they are connected to the internet. 此功能不需要客户端通过 VPN 连接到站点系统服务器。This ability doesn't require the clients to connect via VPN to reach the site system servers.

Configuration Manager 提供两种方法来管理连接了 Internet 的客户端:Configuration Manager provides two ways to manage internet-connected clients:

  • 云管理网关Cloud management gateway

  • 基于 Internet 的客户端管理Internet-based client management

备注

可以将两个服务的组合用于单个站点。You can have a combination of both services for a single site. 如果某个设备从该站点获取 IBCM 和 CMG 的策略,则该设备将在它们之间随机进行通信。If a device gets policy from the site for both IBCM and CMG, then it randomizes between them for communication. 可用于控制通信的唯一机制是客户端身份验证。The only mechanism available to control communication is client authentication. 例如,如果加入 Azure AD 的客户端不信任基于 Internet 的管理点的服务器身份验证证书,则只能使用 CMG。For example, if an Azure AD-joined client doesn't trust the server authentication certificate of the internet-based management point, it can only use the CMG. 如果加入域的客户端不信任 CMG 的服务器身份验证证书,则只能使用基于 Internet 的管理点。If a domain-joined client doesn't trust the server authentication certificate of the CMG, it can only use the internet-based management point.

云管理网关Cloud management gateway

云管理网关可管理基于 Internet 的客户端。The cloud management gateway provides management of internet-based clients. 它将 Microsoft Azure 云服务以及与该服务通信的本地站点系统角色结合使用。It uses a combination of a Microsoft Azure cloud service, and an on-premises site system role that communicates with that service. 基于 Internet 的客户端使用该云服务与本地 Configuration Manager 进行通信。Internet-based clients use the cloud service to communicate with the on-premises Configuration Manager.

CMG 优点CMG advantages

  • 无需额外的本地基础结构投资。No additional on-premises infrastructure investment required.

  • 不会向 Internet 公开本地基础结构。Does not expose on-premises infrastructure to the internet.

  • 运行服务的云虚拟机由 Azure 完全管理且免维护。Cloud virtual machines that run the service are fully managed by Azure and require no maintenance.

  • 可轻松在 Configuration Manager 控制台中进行设置和配置。Easily set up and configured in the Configuration Manager console.

CMG 缺点CMG disadvantages

  • 云订阅费用。Cloud subscription cost.

  • 通过云服务发送的管理数据。Management data sent through cloud service.

有关详细信息,请参阅规划云管理网关For more information, see Plan for cloud management gateway.

基于 Internet 的客户端管理Internet-based client management

此方法依赖于面向 Internet 的站点系统服务器,为了进行管理,客户端会直接与这些服务器通信。This method relies on internet-facing site system servers to which clients directly communicate for management purposes. 它要求配置客户端和站点系统服务器,实现基于 Internet 的客户端管理 (IBCM)。It requires clients and site system servers to be configured for internet-based client management (IBCM).

IBCM 优点IBCM advantages

  • 无云服务依赖关系。No cloud service dependency.

  • 无与云订阅关联的费用。No additional cost associated with a cloud subscription.

  • 可完全控制提供服务的服务器和角色。Full control of servers and roles providing the service.

IBCM 缺点IBCM disadvantages

  • 需要额外的基础结构投资。Require additional infrastructure investment.

  • 额外基础结构的日常管理费用和运营费用。Overhead and operational cost of additional infrastructure.

  • 必须向 Internet 公开基础结构。Infrastructure must be exposed to the internet.

有关详细信息,请参阅规划基于 Internet 的客户端管理For more information, see Plan for internet-based client management.