Skip to content

Commit b802a71

Browse files
committed
ta-scope-INADO-12698965
1 parent 90aebcd commit b802a71

9 files changed

Lines changed: 89 additions & 56 deletions

File tree

memdocs/configmgr/cloud-attach/toc.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,8 +7,8 @@ items:
77
href: enable.md
88
- name: Tenant attach
99
items:
10-
- name: Tenant attach overview
11-
href: ../tenant-attach/device-sync-actions.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json
10+
- name: Tenant attach prerequisites
11+
href: ../tenant-attach/prerequisites.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json
1212
- name: Enable tenant attach
1313
href: ../tenant-attach/device-sync-actions.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json
1414
- name: Use tenant attach

memdocs/configmgr/core/get-started/2021/includes/2103/7958749.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ Microsoft Endpoint Manager is an integrated solution for managing all of your de
1919

2020
### Prerequisites for cloud attach during upgrade
2121

22-
The same prerequisites apply as for tenant attach. For more information, see [Enable tenant attach](../../../../../tenant-attach/device-sync-actions.md#prerequisites).
22+
The same prerequisites apply as for tenant attach. For more information, see [Enable tenant attach](../../../../../tenant-attach/device-sync-actions.md).
2323

2424
The new pages in the Updates Wizard only appear when you update the site from technical preview branch version 2102 or later.
2525

memdocs/configmgr/core/plan-design/changes/whats-new-in-version-2103.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@ The discovery prerequisite for user accounts accessing tenant attach features wi
4949
- Azure Active Directory user discovery
5050
- Active Directory user discovery
5151

52-
For more information, see [Tenant attach prerequisites](../../../tenant-attach/device-sync-actions.md#prerequisites).
52+
For more information, see [Tenant attach prerequisites](../../../tenant-attach/prerequisites.md).
5353

5454
### Application details
5555
<!--8364465-->

memdocs/configmgr/core/understand/product-and-licensing-faq.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -117,7 +117,7 @@ sections:
117117
- [Co-management prerequisites](../../comanage/overview.md#prerequisites)
118118
- [Windows Autopilot requirements](/windows/deployment/windows-autopilot/windows-autopilot-requirements)
119119
- [Desktop analytics prerequisites](../../desktop-analytics/overview.md#prerequisites)
120-
- [Tenant attach prerequisites](../../tenant-attach/device-sync-actions.md#prerequisites)
120+
- [Tenant attach prerequisites](../../tenant-attach/prerequisites.md)
121121
- [Endpoint analytics licensing prerequisites](../../../analytics/overview.md#licensing-prerequisites)
122122
- [Use conditional access with Intune](../../../intune/protect/conditional-access.md#ways-to-use-conditional-access-with-intune)
123123
- [TeamViewer prerequisites](../../../intune/remote-actions/teamviewer-support.md#prerequisites)

memdocs/configmgr/tenant-attach/device-sync-actions.md

Lines changed: 6 additions & 49 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Microsoft Endpoint Manager tenant attach
33
titleSuffix: Configuration Manager
44
description: Upload your Configuration Manager devices to the cloud service and take actions from the admin center.
5-
ms.date: 12/21/2021
5+
ms.date: 03/21/2022
66
ms.topic: conceptual
77
ms.prod: configuration-manager
88
ms.technology: configmgr-core
@@ -17,52 +17,7 @@ ms.collection: highpri
1717
<!--3555758 live 3/4/2020 Configuration Manager version 2002 min-->
1818
*Applies to: Configuration Manager (current branch)*
1919

20-
Microsoft Endpoint Manager is an integrated solution for managing all of your devices. Microsoft brings together Configuration Manager and Intune into a single console called **Microsoft Endpoint Manager admin center**. You can upload your Configuration Manager devices to the cloud service and take actions from the **Devices** blade in the admin center.
21-
22-
## Prerequisites
23-
24-
- An account that is a *Global Administrator* for signing in when applying this change. For more information, see [Azure Active Directory (Azure AD) administrator roles](/azure/role-based-access-control/rbac-and-directory-admin-roles#azure-ad-administrator-roles).
25-
26-
- Onboarding creates a third-party app and a first party service principal in your Azure AD tenant.
27-
28-
- An Azure cloud environment.
29-
30-
- The **Upload to Microsoft Endpoint Manager admin center** option is disabled for Microsoft Azure China 21Vianet (Azure China Cloud) and Azure US Government Cloud.<!--8815787--> Starting in version 2107, this option is available for US Government customers.
31-
32-
- Starting in version 2107, United States Government customers can use the following tenant attach features in the US Government cloud:<!-- 8353823 -->
33-
34-
- Account onboarding
35-
- Tenant sync to Intune
36-
- Device sync to Intune
37-
- Device actions in the Microsoft Endpoint Manager admin center
38-
39-
- At least one Intune license for you as the administrator to access the Microsoft Endpoint Manager admin center. <!--10254915-->
40-
41-
- The [administration service](../develop/adminservice/overview.md) in Configuration Manager needs to be set up and functional. <!--1104776-->
42-
43-
- The user accounts triggering device actions have the following prerequisites:
44-
- The user account needs to be a synced user object in Azure AD (hybrid identity). This means that the user is synced to Azure Active Directory from Active Directory.
45-
- For Configuration Manager version 2103, and later: </br>
46-
Has been discovered with either [Azure Active Directory user discovery](../core/servers/deploy/configure/about-discovery-methods.md#azureaddisc) or [Active Directory user discovery](../core/servers/deploy/configure/about-discovery-methods.md#bkmk_aboutUser). <!--9089764-->
47-
- For Configuration Manager version 2010, and earlier: </br>
48-
Has been discovered with both [Azure Active Directory user discovery](../core/servers/deploy/configure/about-discovery-methods.md#azureaddisc) and [Active Directory user discovery](../core/servers/deploy/configure/about-discovery-methods.md#bkmk_aboutUser).
49-
.
50-
51-
- The **Initiate Configuration Manager action** permission under **Remote tasks** in the Microsoft Endpoint Manager admin center.
52-
- For more information about adding or verifying permissions in the admin center, see [Role-based access control (RBAC) with Microsoft Intune](../../intune/fundamentals/role-based-access-control.md#roles).
53-
54-
- If your central administration site has a [remote provider](../core/plan-design/hierarchy/plan-for-the-sms-provider.md), then follow the instructions for the [CAS has a remote provider](../core/servers/manage/cmpivot-changes.md#cas-has-a-remote-provider) scenario in the CMPivot article. <!--7796824-->
55-
56-
This feature supports all OS versions that Configuration Manager currently supports as a client. For more information, see [Supported OS versions for clients and devices](../core/plan-design/configs/supported-operating-systems-for-clients-and-devices.md).<!-- MEMDocs#545 -->
57-
58-
## Internet endpoints
59-
60-
[!INCLUDE [Internet endpoints for tenant attach](../core/plan-design/network/includes/internet-endpoints-tenant-attach.md)]
61-
62-
Starting in version 2010, the service connection point validates important internet endpoints for tenant attach. These checks help make sure that the cloud service is available. It also helps you troubleshoot issues by quickly determining if network connectivity is a problem. For more information, see [Validate internet access](../core/servers/deploy/configure/about-the-service-connection-point.md#validate-internet-access).<!--8565578-->
63-
64-
> [!NOTE]
65-
> The service connection point checks the CRL. If this server doesn't have access to the URLs listed above, the CRL check fails. Consider setting a system proxy or use the following command: 'netsh winhttp set proxy'. For more information, see [How the Windows Update client determines which proxy server to use to connect to the Windows Update Web site](https://support.microsoft.com/topic/how-the-windows-update-client-determines-which-proxy-server-to-use-to-connect-to-the-windows-update-web-site-08612ae5-3722-886c-f1e1-d012516c22a1). Make sure that you include a bypass list for internal site communications. This configuration may be neccesary as the proxy server settings within Configuration Manager only configure the proxy for Configuration Manager applications and not the underlying OS.
20+
Microsoft Endpoint Manager is an integrated solution for managing all of your devices. Microsoft brings together Configuration Manager and Intune into a single console called **Microsoft Endpoint Manager admin center**. You can upload your Configuration Manager devices to the cloud service and take actions from the **Devices** blade in the admin center. Before you enable tenant attach, verify that the [prerequisites for tenant attach](prerequisites.md) have been met.
6621

6722
## <a name="bkmk_edit"></a> Enable device upload when co-management is already enabled
6823

@@ -128,8 +83,6 @@ When co-management isn't enabled, use the instructions below to enable device up
12883
[![Device overview in Microsoft Endpoint Manager admin center](./media/3555758-device-overview-actions.png)](./media/3555758-device-overview-actions.png#lightbox)
12984

13085

131-
[!INCLUDE [Import a previously created Azure AD application](includes/import-azure-app.md)]
132-
13386
## Display the Configuration Manager connector status from the admin console
13487
<!--IN9229333, CM7138634-->
13588
From the Microsoft Endpoint Manager admin center, you can review the status of your Configuration Manager connector. To display the connector status, go to **Tenant administration** > **Connectors and tokens** > **Microsoft Endpoint Configuration Manager**. Select a Configuration Manager hierarchy to display additional information about it.
@@ -167,6 +120,10 @@ When you offboard a hierarchy from the admin center, it may take up to two hours
167120
> [!NOTE]
168121
> If you are using custom [RBAC roles with Intune](../../intune/fundamentals/role-based-access-control.md#roles), you will need to grant the **Organization** > **Delete** permission to offboard a hierarchy.
169122
123+
124+
[!INCLUDE [Import a previously created Azure AD application](includes/import-azure-app.md)]
125+
126+
170127
## Next steps
171128

172129
- [Enroll Configuration Manager devices into Endpoint analytics](../../analytics/enroll-configmgr.md#bkmk_cm_enroll)
Lines changed: 74 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,74 @@
1+
---
2+
title: Microsoft Endpoint Manager tenant attach prerequisites
3+
titleSuffix: Configuration Manager
4+
description: Prerequisites for Microsoft Endpoint Manager tenant attach.
5+
ms.date: 03/21/2022
6+
ms.topic: conceptual
7+
ms.prod: configuration-manager
8+
ms.technology: configmgr-core
9+
manager: dougeby
10+
author: mestew
11+
ms.author: mstewart
12+
ms.localizationpriority: high
13+
ms.collection: highpri
14+
---
15+
16+
# Microsoft Endpoint Manager tenant attach: Prerequisites
17+
<!--3555758 live 3/4/2020 Configuration Manager version 2002 min-->
18+
*Applies to: Configuration Manager (current branch)*
19+
20+
Microsoft Endpoint Manager is an integrated solution for managing all of your devices. Microsoft brings together Configuration Manager and Intune into a single console called **Microsoft Endpoint Manager admin center**. You can upload your Configuration Manager devices to the cloud service and take actions from the **Devices** page in the admin center. Some of the features you may want to use include:
21+
22+
- Run PowerShell [scripts](scripts.md)
23+
- Install [applications](applications.md)
24+
- Query devices with [CMPivot](../tenant-attach/cmpivot-samples-attached.md?toc=/mem/configmgr/cloud-attach/toc.json&bc=/mem/configmgr/cloud-attach/breadcrumb/toc.json)
25+
- Display a [timeline](timeline.md) of events from the device
26+
27+
## Prerequisites
28+
29+
- An account that is a *Global Administrator* for signing in when applying this change. For more information, see [Azure Active Directory (Azure AD) administrator roles](/azure/role-based-access-control/rbac-and-directory-admin-roles#azure-ad-administrator-roles).
30+
31+
- Onboarding creates a third-party app and a first party service principal in your Azure AD tenant.
32+
33+
- An Azure cloud environment.
34+
35+
- The **Upload to Microsoft Endpoint Manager admin center** option is disabled for Microsoft Azure China 21Vianet (Azure China Cloud) and Azure US Government Cloud.<!--8815787--> Starting in version 2107, this option is available for US Government customers.
36+
37+
- Starting in version 2107, United States Government customers can use the following tenant attach features in the US Government cloud:<!-- 8353823 -->
38+
39+
- Account onboarding
40+
- Tenant sync to Intune
41+
- Device sync to Intune
42+
- Device actions in the Microsoft Endpoint Manager admin center
43+
44+
- At least one Intune license for you as the administrator to access the Microsoft Endpoint Manager admin center. <!--10254915-->
45+
46+
- The [administration service](../develop/adminservice/overview.md) in Configuration Manager needs to be set up and functional. <!--1104776-->
47+
48+
- The user accounts triggering device actions have the following prerequisites:
49+
- The user account needs to be a synced user object in Azure AD (hybrid identity). This means that the user is synced to Azure Active Directory from Active Directory.
50+
- For Configuration Manager version 2103, and later: </br>
51+
Has been discovered with either [Azure Active Directory user discovery](../core/servers/deploy/configure/about-discovery-methods.md#azureaddisc) or [Active Directory user discovery](../core/servers/deploy/configure/about-discovery-methods.md#bkmk_aboutUser). <!--9089764-->
52+
- For Configuration Manager version 2010, and earlier: </br>
53+
Has been discovered with both [Azure Active Directory user discovery](../core/servers/deploy/configure/about-discovery-methods.md#azureaddisc) and [Active Directory user discovery](../core/servers/deploy/configure/about-discovery-methods.md#bkmk_aboutUser).
54+
.
55+
56+
- The **Initiate Configuration Manager action** permission under **Remote tasks** in the Microsoft Endpoint Manager admin center.
57+
- For more information about adding or verifying permissions in the admin center, see [Role-based access control (RBAC) with Microsoft Intune](../../intune/fundamentals/role-based-access-control.md#roles).
58+
59+
- If your central administration site has a [remote provider](../core/plan-design/hierarchy/plan-for-the-sms-provider.md), then follow the instructions for the [CAS has a remote provider](../core/servers/manage/cmpivot-changes.md#cas-has-a-remote-provider) scenario in the CMPivot article. <!--7796824-->
60+
61+
This feature supports all OS versions that Configuration Manager currently supports as a client. For more information, see [Supported OS versions for clients and devices](../core/plan-design/configs/supported-operating-systems-for-clients-and-devices.md).<!-- MEMDocs#545 -->
62+
63+
## Internet endpoints
64+
65+
[!INCLUDE [Internet endpoints for tenant attach](../core/plan-design/network/includes/internet-endpoints-tenant-attach.md)]
66+
67+
Starting in version 2010, the service connection point validates important internet endpoints for tenant attach. These checks help make sure that the cloud service is available. It also helps you troubleshoot issues by quickly determining if network connectivity is a problem. For more information, see [Validate internet access](../core/servers/deploy/configure/about-the-service-connection-point.md#validate-internet-access).<!--8565578-->
68+
69+
> [!NOTE]
70+
> The service connection point checks the CRL. If this server doesn't have access to the URLs listed above, the CRL check fails. Consider setting a system proxy or use the following command: 'netsh winhttp set proxy'. For more information, see [How the Windows Update client determines which proxy server to use to connect to the Windows Update Web site](https://support.microsoft.com/topic/how-the-windows-update-client-determines-which-proxy-server-to-use-to-connect-to-the-windows-update-web-site-08612ae5-3722-886c-f1e1-d012516c22a1). Make sure that you include a bypass list for internal site communications. This configuration may be neccesary as the proxy server settings within Configuration Manager only configure the proxy for Configuration Manager applications and not the underlying OS.
71+
72+
## Next steps
73+
74+
- [Enable tenant attach](device-sync-actions.md)

memdocs/configmgr/tenant-attach/toc.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ items:
33
href: index.yml
44
- name: Deploy and use
55
items:
6+
- name: Prerequisites for tenant attach
7+
href: prerequisites.md
68
- name: Enable tenant attach
79
href: device-sync-actions.md
810
- name: Client details

memdocs/configmgr/tenant-attach/troubleshoot-client-details.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -81,7 +81,7 @@ Typically, this error is caused by an issue with the admin account. Below are th
8181
8282
**Error message:** Error validating request. Verify that the Configuration Manager service connection point can reach the internet endpoints required for tenant attach.
8383
84-
**Possible causes:** Typically this error is seen when URLs that are needed by tenant attach are blocked. If the service connection point can't access the needed internet endpoints, a validation error will occur. For more information, see [Internet endpoints](device-sync-actions.md#internet-endpoints).
84+
**Possible causes:** Typically this error is seen when URLs that are needed by tenant attach are blocked. If the service connection point can't access the needed internet endpoints, a validation error will occur. For more information, see [Internet endpoints](prerequisites.md#internet-endpoints).
8585
8686
## <a name="bkmk_1603"></a> Unexpected error occurred
8787

memdocs/configmgr/tenant-attach/troubleshoot.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -119,7 +119,7 @@ Validating device action message content...
119119
Unauthorized to perform client action. TemplateID: RequestMachinePolicy TenantId: a1b2c3a1-b2c3-d4a1-b2c3-d4a1b2c3a1b2 AADUserID: 3a1e89e6-e190-4615-9d38-a208b0eb1c78
120120
```
121121

122-
Ensure the user running the action from the Microsoft Endpoint Manager admin center has the required permissions on Configuration Manager site. For more information, see [Microsoft Endpoint Manager tenant attach prerequisites](device-sync-actions.md#prerequisites).
122+
Ensure the user running the action from the Microsoft Endpoint Manager admin center has the required permissions on Configuration Manager site. For more information, see [Microsoft Endpoint Manager tenant attach prerequisites](prerequisites.md).
123123

124124

125125

0 commit comments

Comments
 (0)