Remote users unable to see software deployments while off VPN

Charlie Dobson 116 Reputation points
2021-03-26T18:23:10.27+00:00

I'm using Endpoint Manager Current Branch 2006 with a single site configuration. I recently setup an external server in our DMZ that hosts the DP, MP, and SUP roles that appears to be healthy (Site Status & Component Status both indicate all green). I've verified external access to our server using https://fqdn.server.com/sms_mp/.sms_aut?mplist and can see both the internal and external MPs listed in the XML output.

All software that is distributed to our internal server is also distributed to our external server so that they can be downloaded whether connected to VPN or not, and all software is made available to everyone (we use the Administrator Approval option for licensed software installs). Yet, when users are not on VPN they see only a handful of software, not the entire list. And attempts to install the few software that are available ends up in error.

We are using PKI in our environment, but we setup the DMZ server to use a third-party certificate for both the Default website and the Windows Update site in IIS. Not sure if that's relevant or not. I've verified by looking at ClientLocation.log that external devices are set to Internet and have confirmed by DMZ server is set to be in the Internet boundary group. I've also tried looking in AppDiscovery.log, AppEnforce.log, ExecMgr.log, but not seeing anything that immediately stands out.

If the user connects to VPN they can see all software, but not off VPN. I suspect there's a problem when polling the DP for available software but not sure where else to check.

Microsoft Configuration Manager Application
Microsoft Configuration Manager Application
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Application: A computer program designed to carry out a specific task other than one relating to the operation of the computer itself, typically to be used by end users.
480 questions
Microsoft Configuration Manager
0 comments No comments
{count} votes

Accepted answer
  1. Jason Sandys 31,286 Reputation points Microsoft Employee
    2021-03-29T03:25:15.29+00:00

    Is the software not shown when they are not connected to the VPN deployed to user-based collections?

    Note that DPs have nothing to do with what is shown in Software Center.


1 additional answer

Sort by: Most helpful
  1. HanyunZhu-MSFT 1,846 Reputation points Microsoft Vendor
    2021-03-29T09:46:38.3+00:00

    Hi, @ CharlieDobson

    Thanks for posting in Microsoft Q&A forum.

    Please check whether the FQDN of external network is configured.

    You can check it on the client computers in Network tab of Configuration Manager.

    1. Navigate to Configuration Manager in the Control Panel of the client computer, and then double-click to open its properties.
    2. On the Network tab, check whether the FQDN of your internet-based management point in the FQDN text box is configured. For example: mp.yourorganisation.com.
      82280-a.png

    Thanks for your time.


    If the response is helpful, please click "Accept Answer"and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.