CB 2002 / CMG using Token Based Authentification problem

Peter C. Jackson 21 Reputation points
2020-09-10T07:12:47.197+00:00

Hi,

We have upgraded to CB 2002 and are trying to get the CMG Client connection to work.

The Onsite connection to Azure and back is working correctly.

What we have in place is a PKI to assign Certificates for Wifi access, the CCM Client keeps choosing this as its CCM PKI Certificate.
and therefore tries to connect to the CMG using an invalid Certificate.

We would really like to use the Token Based certificate offered since CB 2002.

Is there a way to prevent CCM Client using the certificate?
There is only 1 certificate in the personal store.

Does CCM look only inside the personal store?

Microsoft Configuration Manager Deployment
Microsoft Configuration Manager Deployment
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Deployment: The process of delivering, assembling, and maintaining a particular version of a software system at a site.
923 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Jörgen Nilsson 186 Reputation points
    2020-09-10T08:53:12.14+00:00

    Hi,
    We had the same issue, we ended up with Hybrid Azuread Joining the devices instead which solves the problem as well, switching to HTTPS in the site will of course also solve the problem.
    This topic was discussed at the AMA at an online event two weeks ago called WPNinjas.eu and I believe the response from the PG was that it is by design and it will try to use the Cert. Workaround Hybrid AzureAD Join or HTTPS.

    And yes, the CM client will try to use a cert in the Personal Store of the device.
    Regards,
    Jörgen

    0 comments No comments

  2. Jason Sandys 31,186 Reputation points Microsoft Employee
    2020-09-10T17:54:13.077+00:00

    Jorgen is correct that at this time, that's the defined behavior. There is an item in the backlog to address this behavior, but I don't know when or if it will be addressed.

    I suggest that you file feedback in the ConfigMgr console and create a UserVoice item (or upvote an existing one) if this is an issue for your org.

    0 comments No comments