MECM Configuration and Upgrading for Airgapped Environment

Michael Little 0 Reputation points
2025-02-24T13:36:25.6533333+00:00

I have tinkered with SCCM many years ago, but never really dove into the application really deep since it was not a server that I managed. Now, I am looking to install and use MECM in the environment that I support. The IT admins that typically image systems use a third-party application along with passing a USB hard drive. I am trying to improve how they image and deploy new systems by implementing a MECM server. Microsoft surely knows how to over complicate a system. I have MECM installed and I am able to image systems, but I am having issues deploying the MECM client to workstations as well as apply updates to these systems. I tried to push the client as well as manually install the client, but my workstations still show up as unknown. The only client to show as having the client installed is my MECM server.

My MECM server is set up in an airgapped environment. At the current time, I am in the "testing" phase, so if I need to blow the server away an reinstall it is possible. Since MECM requires an Active Directory environment, I added the ADDS role to my server. At the current time, all services are running on the same server (ADDS, MECM, WSUS). It is taking a lot of reading and watching of videos, but I still don't have things working properly. As mentioned above, I am able to image systems using a task sequence, but just can't figure out the last few things. Ultimately, I am looking to use this offline environment for imaging of systems as well as applying updates and configurations for securing the systems. Once the systems are hardened, they will be moved to a scanning environment where they will be scanned for vulnerabilities prior to moving them to our production environment.

Since my MECM environment does not have Internet connectivity, how can I upgrade to the latest version (2409)? For Windows Updates, I am utilizing an Online/Offline WSUS model. Hopefully, this will be the only areas where we will utilize USB hard drives moving forward. Feel free to make any recommendations to resolve my issues and better our environment.

--Michael L. Little CISSP, CCNA, CySA+

Microsoft Configuration Manager Application
Microsoft Configuration Manager Application
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Application: A computer program designed to carry out a specific task other than one relating to the operation of the computer itself, typically to be used by end users.
515 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. AllenLiu-MSFT 48,356 Reputation points Microsoft Vendor
    2025-02-25T02:47:38.95+00:00

    Hi,

    Thank you for posting in Microsoft Q&A forum.

    To upgrade your MECM to the latest version (2409), you may configure your service connection point in offline mode and use the service connection tool to upgrade.

    https://learn.microsoft.com/en-us/mem/configmgr/core/servers/manage/use-the-service-connection-tool

    For the client push issue, you may start from checking ccmsetup.log on client.

    https://learn.microsoft.com/en-us/mem/configmgr/core/plan-design/hierarchy/log-files#BKMK_ClientInstallLog


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Add comment".


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.