Trouble installing SCCM Client on Workgroup system using bulk enrollment token

Dean 1 Reputation point
2021-03-03T20:49:39.987+00:00

I am trying to experiment with the bulk enrollment feature of our SCCM Version 2010 environment. I have created the bulk enrollment token, and copied it to my installation USB drive. The CCMSetup.log shows CCM_E_NO_TOKEN_AUTH, followed by a DownloadFilebyWinHTTP error 0x87d00455. I would like to validate the Token is actually being used, and is being recognized at the CMG. I have an internally generated cert manageing the traffic between my CMG, and the connection point on-prem, My intention is to use eHTTP for client communication, but this system isn't AD, or AAD joined (yet). Can anyone offer any advice where to begin looking? TY!

Microsoft Configuration Manager
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Jason Sandys 31,286 Reputation points Microsoft Employee
    2021-03-04T00:56:49.433+00:00

    Does the client device trust the PKI that issued the cert used for the CMG?


  2. Dean 1 Reputation point
    2021-03-04T15:04:11.513+00:00

    Hi Jason, No the client is an out-of-the box system fresh off the shelf. I thought the token was the authentication key, to bypass any on-prem/AD cert requirements. I was expecting to deliver the client, then a VPN client, and then perform an AD join, and move the client into a fully managed state. We are not co-managing at this point, (hopefully soon) but this was "my" way to leverage the CMG for those new systems. Thanks


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.