ConfigMgr 2006 introduced a new option to help remote worker scenarios. I have explained how to optimize ConfigMgr infrastructure for remote workers. Let’s see how to enable access for ConfigMgr Intranet Clients can Use CMG Software Update Point.
TL;DR
Introduction
From the 2006 version onwards, the ConfigMgr intranet clients can access CMG software update point. The CMG SUP should be assigned to a boundary group.
The ConfigMgr Intranet Clients can use the CMG Software Update Point option as another option to help and enable the remote workers scenarios. Microsoft introduced a new set of ConfigMgr Management Insights called Optimize for Remote Workers.
- When an internet machine connects to the VPN, it will continue scanning against the CMG software update point over the internet.
- If the only software update point for the boundary group is the CMG software update point, then all intranet and internet devices will scan against it.
Allow Configuration Manager Cloud Management Gateway traffic
Let’s enable the option to allow SCCM CMG traffic for intranet client devices connected through a VPN.
- Navigate to \Administration\Overview\Site Configuration\Servers and Site System Roles
- Click on the site system server where you have installed Software Update Point

- Right-click on Software Update Point site system role
- Select Properties options

- On the General Tab (ConfigMgr 2006 onwards)
- Select the option called “Allow Configuration Manager Cloud Management Gateway traffic“
- Click OK

Boundary Group
Make sure you have added the CMG Software Update Point to the Boundary group to make sure the VPN clients will receive the details of CMG server.

Logs
Client-side validation can be done using locationservices.log. Make sure you have CMG related entry in the log file to confirm the changes at the client side.
Resources
- SCCM CMG SUP selection option for intranet client
- ConfigMgr Management Insights – https://docs.microsoft.com/en-us/sccm/core/servers/manage/management-insights
If our company does not use SCCM for Software updates, only application deployment, can we use the CMG
Yes you can use CMG for application deployment. Make sure that all the required applications are distributed to the cloud DP
I have different VPN connections from different geographical locations. Also different Secondary sites. Do i have to allow network access between VPN network and server network to get information about CMG point.
You might need split tunnelling in this scenario when clients are connected via VPN … cmg connection should go out to internet directly using the split