Create System Management Container for SCCM | ConfigMgr

2
Create System Management Container

Let’s learn how to Create System Management Container & provide full control permissions. System Management is the container in the Active Directory to manage devices using ConfigMgr | SCCM.

NOTE! – You need to Extend Active Directory Schema before creating system management container.

System Management Container

ConfigMgr uses System management container to publish Management Point & Boundary details. ConfigMgr clients connect & query system management container to select the best MP available.

NOTE! – More details about Publishing site data for SCCM.

Prerequisite

  • Login with user permission to Create All Child Objects permission on the System container for each domains. More details here.
  • Create this container one time in each domain that has a primary or secondary site server that will publish data to Active Directory.
  • Grant FULL Control permissions to the computer account of each primary and secondary site server
Altaro Office 365 Backup
Advertisement Altaro Office 365 Backup

Create System Management Container

Let’s see how to create system management container.

  • Run ADSI Edit (adsiedit.msc)
  • Right Click on ADSI Edit node from MMC console and click on Connect to…
ADSI Edit.MSC Connect To - Create System Management Container
ADSI Edit.MSC Connect To – Create System Management Container
  • Enter the site server’s Domain or Domain server details – Select or type a domain or server: (Server | Domain [:port])
  • Click OK
Select or type a domain or server - Create System Management Container
Select or type a domain or server – Create System Management Container
  • Expand Domain -> expand
  • Right-click CN=System
  • Select New, and then choose Object
Select New, and then choose Object
Select New, and then choose Object
  • In the Create Object dialog box, choose Container, and then choose Next
System Management Container
System Management Container
  • In the Value box, enter System Management, and then choose Next to continue
System Management Container Creation
System Management Container Creation
  • Click on Finish button
Completed the Creation of System Management Container
Completed the Creation of System Management Container

Assign Permission

You have created the System Management container. Now let’s assign permissions to primary and secondary server computer accounts.

  • Right-click CN=System Management, and then choose Properties
System Management -> Properties
System Management -> Properties
  • Select the Security tab from System Management Properties
Select Security Tab from System Management Properties
Select Security Tab from System Management Properties
  • Click on Add button
  • Enter the site server computer account in the box below “Enter the object names to select
  • Click on Object Types
Add computer accounts of SCCM Site System Servers
Add computer accounts of SCCM Site System Servers
  • Select Computers and Click OK
Select the Types of Objects you want to find
Select the Types of Objects you want to find
  • Click on OK to continue with selection
Add the site system server access to System Management container
Add the site system server access to System Management container
  • Select on the Site System Computer account
  • Select the Full Control permission
    • Repeat this step for all the site server in this domain
  • Click on Advanced button
Advanced - Full Control - System Container
Advanced – Full Control – System Management Container
  • Select the site server’s computer account
  • Select Edit button
Assign Full access rights
Assign Full access rights
  • Select drop down option called “This object and all descendant objects” from Applies to option
  • Click OK to continue
This object and all descendant objects - System Management Container
This object and all descendant objects – System Management Container
  • Click OK & OK to finish

Results

Now you have created System Management container and provided full control permission to site system servers.

Create System Management Container for SCCM | ConfigMgr 1

Resources

2 COMMENTS

  1. Hi, Anoop,
    One question: we have in our company a primary SCCM site, and we are going to create another one in parallel, to migrate from the old to the new, different name of site, we have problems with the S.O etc, would there be any problem in adding the new server in the container, along with the other one? with the same permissions.

    Thank you very much for your help!

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.