SCOM Gateway Server Requirements for Workgroup Environments

Williams 155 Reputation points
2023-11-21T16:01:08.9933333+00:00

Hello,

Is it necessary for the SCOM Gateway Server to be domain-joined when monitoring workgroup computers with SCOM? Additionally, what steps should I take if I want to discover workgroup computers using SCOM?

Operations Manager
Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,420 questions
0 comments No comments
{count} votes

Accepted answer
  1. SChalakov 10,271 Reputation points MVP
    2023-11-22T08:34:32.9633333+00:00

    Hi,

    no, it is not required for the GW to be domain-joined, but it could make the setup easier if it is. Let me explain why.

    If your Gateway is in the same domain as your Management Servers (the servers the Gateway reports to) then you don't need to create certificates on your Management Servers. What you still need is a a certificate on your Gateway and also certificates on each Workgroup computer you need to monitor.

    In case that the Gateway and the Management Servers are in different domains, then you need certificates on all three instances - on your Management Server(s), on your Gateway(s) and of course on ech monitored computer (Workgroup). Alex already pointed this out.

    Of course all three instances must get certificates coming from the same CA, so that the setup can work.

    I hope I could help you with that. Please don't hesitate to ask further questions if something is not clear.


    (If the reply was helpful please don't forget to upvote and/or accept as answer, thank you)
    Regards
    Stoyan Chalakov

    2 people found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. AlexZhu-MSFT 5,551 Reputation points Microsoft Vendor
    2023-11-22T05:33:19.8266667+00:00

    Hi,

    The gateway server can be either workgroup or domain joined.

    There are three major things that we need to have ready and in place before proceeding with the gateway role installation in a standard scenario:

    1, Certificates need to be generated for the gateway and management server(s) and installed into the certificate stores. 
        If the gateway and client servers are being used in a Workgroup scenario, then the clients also need certificates. 
    2, The intended gateway server needs to be "Approved" to be a gateway within the management group before installation. 
    3, Port 5723 must be opened between the gateway and management server
    
    

    https://learn.microsoft.com/en-us/system-center/scom/deploy-install-gateway-server?view=sc-om-2022&tabs=install-using-the-gui

    For the detailed steps for workgroup scenarios, we can refer to this step-by-step guide:

    https://www.souravmahato.com/procedure-to-install-the-scom-agent-on-workgroup-server/

    note: this is not from Microsoft, just for your reference.

    Regards,

    Alex

    0 comments No comments