DSC is typically dynamic and enforces the correct configuration normally every 15 minutes which greatly helps ensure secure configurations. Primarily aimed at mobile devices, this style of configuration is increasingly applicable to Windows Desktops with the advent of Windows Not everything on the desktop can yet be controlled this way, even with W10 but many key settings and controls are already available. A much simpler method for enforcing desktop settings than the other methods, it allows fewer administrators and much less specialist knowledge.
The article from FoxDeploy covers the first three of those and lays out the purpose of each. Well worth a read. What is missing is the 4th method which uses Mobile Device Management tooling. The leading contender for this is Microsoft InTune. However, InTune is really only focussed on Windows 10 desktop and mobile , it has limited control in other Operating Systems.
Servers only ever exist in a given state. If they deviate or we make changes, we refactor and redeploy. DSC drives it all and the machine will be up and running on a new OS, with data migrated in a matter of minutes. For all practical purposes, the first true large scale management tool we had for Windows systems in the modern era was Group Policy, or GPO as it is commonly truncated.
Comparatively, SCCM and MDT allow us to we import an image from a Windows install disk and then run dozens of individual steps which are customized based on the target machines platform, model, office location and other factors.
Register now or log in to join your professional community. In GPOs, you can use. MSI packages and shoud be connected to AD, and there is no centralized reporting for patch deployment,.
WSUS the Microsoft's basic offering for enterprise OS and Microsoft application patching, Easy to configure and it will be connect to Microsoft's update catalogue, you can do schedules rollouts by groups.
This builds on top of the WSUS infrastructure and components and gives you more configuration and reporting, In addition to patching SCCM also can be used for software packaging, and deployment, OS deployment. System Center Essentials is a multi-server monitoring solution that uses a single console its good for small business, It can be used as patch management software for Microsoft products, but it isn't really intended to manage third-party patches like SCCM.
These capabilities minimize the impact of software distribution and reduce bandwidth requirements. Robust packaging options— Software distribution using group policy is generally restricted to MSI software packages.
You can deploy non-MSI files with group policy, but they are deployed as voluntary applications—rather than mandatory software distributed to the user. You can even create a package that just executes a set of command lines.
With that being said,. Truthfully, if you are even considering using GPO then your organization is likely to be small and if this is the case then take a look at SCE. Office Office Exchange Server. Not an IT pro? Sign in. United States English. Ask a question. Quick access. Search related threads.
Remove From My Forums. Answered by:. Archived Forums. Configuration Manager General.
0コメント