Introduction
This is Day 9 Part 5 of the Microsoft Configuration Manager interview series.
The first four parts covered:
- Configuration Manager architecture and administration
- Clients, boundaries and collections
- Application deployment and Software Center
- Software Updates, WSUS, SUP and ADRs
- Operating System Deployment, Task Sequences, PXE and WinPE
This final part focuses on the remaining senior-level areas that are frequently discussed in production environments and interviews:
- Hardware Inventory
- Software Inventory
- Discovery Data Records
- Compliance Settings
- Configuration Items
- Configuration Baselines
- Client Health
- Co-management
- Tenant Attach
- Cloud Attach
- Cloud Management Gateway
- Internet-based client management
- SQL and Reporting troubleshooting
- Advanced production scenarios
- End-to-end troubleshooting methodology
The goal is not to repeat the deployment, patching or OSD questions already covered in the previous parts.
1. What is Hardware Inventory in Configuration Manager?
Answer:
Hardware Inventory collects information about the hardware and related configuration of Configuration Manager clients.
Examples include:
- Computer manufacturer and model
- BIOS information
- Processor
- Memory
- Disk information
- Network adapters
- Operating system information
- Installed devices
- Selected WMI-based information
Hardware Inventory must be enabled through Client Settings.
When the client performs a hardware inventory cycle, the collected information is sent to the Management Point and eventually stored in the Configuration Manager site database.
Microsoft documents this flow as:
Client → Management Point → Site Server → Site Database
Hardware Inventory is therefore useful for asset reporting, hardware lifecycle planning, troubleshooting and collection queries.
2. What is the difference between Hardware Inventory and Software Inventory?
Answer:
They collect different types of information.
Hardware Inventory
Primarily collects hardware and configuration information through supported inventory classes.
Examples:
- RAM
- CPU
- BIOS
- Disk
- Network adapter
- Computer system information
Software Inventory
Collects information about files on client computers according to the configured Software Inventory settings.
For example, you can configure it to inventory specific file types and locations.
The important interview point is:
Hardware Inventory and Software Inventory are separate inventory mechanisms and should not be treated as interchangeable.
Software Inventory can generate significant client and network activity if configured broadly, so it should be designed carefully.
3. How does Hardware Inventory work from the client to the database?
Answer:
The basic flow is:
Configuration Manager Client
|
| Hardware Inventory Cycle
v
Management Point
|
v
Configuration Manager Site Server
|
v
Site Database
The client gathers the configured inventory information.
The information is sent to the Management Point.
The Management Point forwards the inventory data to the site server, which processes it and stores the resulting inventory information in the site database.
If inventory appears outdated, troubleshoot each stage instead of immediately assuming that SQL is the problem.
4. How do you enable Hardware Inventory?
Answer:
Hardware Inventory is configured through Client Settings.
In the Configuration Manager console:
Administration → Client Settings
Open the applicable client settings and configure:
Hardware Inventory → Enable hardware inventory and settings
You should also review:
- Inventory schedule
- Inventory classes
- Client Settings precedence
- Whether the affected client actually receives those Client Settings
A common mistake is enabling Hardware Inventory in one Client Setting object while the client is actually receiving another policy with different settings.
5. How can you extend Hardware Inventory?
Answer:
Configuration Manager provides configurable hardware inventory classes.
If the default inventory does not contain a required attribute, an administrator can extend the inventory configuration to collect supported WMI information.
The important consideration is to collect only information that has a genuine administrative or reporting requirement.
For example, blindly adding large numbers of WMI classes can increase:
- Client processing
- Inventory size
- Network traffic
- Database growth
- Processing workload
Therefore, inventory extension should be controlled and tested before production rollout. Microsoft supports extending hardware inventory through the inventory configuration.
6. A client is showing old Hardware Inventory data. How would you troubleshoot it?
Answer:
I would troubleshoot from the client outward.
Step 1 – Verify Client Health
Check whether the Configuration Manager client is functioning.
Get-Service CcmExec
The service should normally be running.
Step 2 – Check Client Settings
Verify:
- Hardware Inventory is enabled
- The client receives the expected Client Settings
- Inventory schedule is appropriate
Step 3 – Check Inventory Logs
Review:
InventoryAgent.log
This helps determine whether the inventory cycle is starting and processing correctly.
Step 4 – Check Management Point Communication
Confirm that the client can communicate with its Management Point.
Step 5 – Check Server-Side Processing
If the client successfully sends inventory but the console remains outdated, investigate server-side inventory processing and the site database.
This approach prevents wasting time troubleshooting SQL when the actual problem is on the client.
7. What is the purpose of InventoryAgent.log?
Answer:
InventoryAgent.log is a key client-side log for inventory processing.
It can help troubleshoot:
- Hardware Inventory
- Inventory cycle initiation
- Inventory processing
- Inventory-related errors
- Whether inventory is being generated
For an inventory problem, this should normally be one of the first logs reviewed on the affected client.
8. What is the difference between inventory data and a Discovery Data Record (DDR)?
Answer:
This is an important distinction.
Inventory
Inventory collects information about an existing Configuration Manager client and its hardware/software state.
DDR
A Discovery Data Record (DDR) is generated by Configuration Manager discovery mechanisms to provide information about discovered resources.
A DDR is therefore related to resource discovery, not hardware inventory.
Do not answer an interview question by saying that a DDR is the same thing as a hardware inventory record.
9. What is Software Inventory?
Answer:
Software Inventory is a Configuration Manager client feature that can collect information about files on client computers.
You configure:
- File types
- Locations
- Inventory behavior
It can then be used to identify files that exist on managed computers.
However, Software Inventory should not automatically be considered the best method for determining every installed application.
For modern environments, application detection, Hardware Inventory, registry information, PowerShell, CMPivot and other supported mechanisms may be more appropriate depending on the requirement.
10. What are the disadvantages of using Software Inventory excessively?
Answer:
A poorly designed Software Inventory configuration can create unnecessary overhead.
Potential effects include:
- Increased client processing
- Increased network traffic
- Larger inventory data
- More server-side processing
- Increased database growth
For example, asking thousands of computers to search large sections of their disks for multiple file types can be unnecessarily expensive.
Therefore:
Inventory should be designed around a specific administrative requirement rather than collecting everything possible.
11. What is Discovery Data Manager?
Answer:
Discovery Data Manager is a site component involved in processing discovery information received from clients and discovery methods.
Discovery information is used to create and maintain Configuration Manager resources.
Do not confuse discovery processing with inventory processing.
A useful conceptual distinction is:
Discovery
↓
Creates/updates resources
Inventory
↓
Collects hardware/software state of clients
12. How would you troubleshoot a discovery problem?
Answer:
First identify which discovery method is involved.
Examples include:
- Active Directory User Discovery
- Active Directory Group Discovery
- Active Directory System Discovery
- Active Directory Forest Discovery
- Heartbeat Discovery
- Network Discovery
Then verify:
- Discovery method is enabled.
- Correct locations are configured.
- Discovery account has appropriate permissions where required.
- Discovery schedule has run.
- Discovery-related logs contain successful processing.
- The resource appears in the appropriate Configuration Manager collection/resource view.
Do not troubleshoot discovery by starting with SQL unless the evidence points toward a site database problem.
13. What is the purpose of Compliance Settings?
Answer:
Configuration Manager Compliance Settings allow administrators to evaluate whether devices conform to defined configuration requirements.
For example, an organization might require:
- A registry setting to have a specific value
- A service to be running
- A security configuration to be enabled
- A particular configuration to exist
- A specific setting to meet organizational standards
Compliance Settings are based around Configuration Items and Configuration Baselines.
14. What is a Configuration Item (CI)?
Answer:
A Configuration Item defines a configuration requirement that Configuration Manager can evaluate.
A CI can contain:
- Discovery settings
- Compliance rules
- Supported platforms
- Remediation behavior where applicable
For example:
“The Windows Firewall service must be running.”
That requirement can be represented through a Configuration Item.
A CI is therefore a building block of compliance configuration.
15. What is a Configuration Baseline?
Answer:
A Configuration Baseline is a collection of configuration items that are evaluated together.
For example:
Baseline: Corporate Security Baseline
├── Firewall enabled
├── Required registry setting
├── Required service configuration
└── Security configuration requirement
The baseline can then be deployed to a collection and evaluated for compliance.
Microsoft defines Configuration Baselines as a core component of Configuration Manager Compliance Settings.
16. What is the difference between a Configuration Item and a Configuration Baseline?
Answer:
Think of it this way:
Configuration Item
One configuration requirement or logical set of requirements.
Configuration Baseline
A collection of Configuration Items that are evaluated together.
Example:
Configuration Items
|
+---- Firewall
|
+---- Registry
|
+---- Service
|
v
Configuration Baseline
|
v
Compliance Evaluation
This distinction is commonly asked in senior Configuration Manager interviews.
17. Can Configuration Manager remediate a non-compliant setting?
Answer:
Yes, where the particular Configuration Item and compliance rule support remediation.
For example, a baseline could detect that a required configuration is incorrect and, where configured, attempt to remediate it.
However, remediation should not be enabled blindly.
Before enabling automatic remediation, determine:
- What will be changed?
- What is the expected state?
- Could the change affect production?
- Is rollback possible?
- Could remediation create a service outage?
In production, test remediation with a pilot collection first.
18. How would you troubleshoot a Configuration Baseline that reports incorrect compliance?
Answer:
I would verify the evaluation from the client side.
Step 1
Confirm the client received the baseline policy.
Step 2
Verify the Configuration Item discovery method.
For example:
- Registry
- WMI
- File
- Script
- Other supported setting types
Step 3
Check the compliance rule.
Make sure the expected value is correct.
For example:
Expected:
Enabled
Actual:
Disabled
Step 4
Review compliance-related client logs.
Important logs include:
CIAgent.log
DCMAgent.log
DCMReporting.log
Step 5
Confirm that the baseline deployment applies to the device.
A common mistake is troubleshooting the CI itself when the actual issue is that the device never received the baseline deployment.
19. What is the difference between Compliance Settings and Application Detection?
Answer:
They solve different problems.
Application Detection
Determines whether a particular application deployment is considered installed.
Compliance Settings
Evaluates whether a device configuration meets a defined requirement.
For example:
Application Detection:
Is Microsoft Edge version X installed?
Compliance:
Is Windows Firewall enabled?
Do not use application detection logic and compliance baselines as though they were the same mechanism.
20. What is Configuration Manager client health?
Answer:
Client health refers to whether the Configuration Manager client is functioning correctly enough to perform management operations.
A healthy client should generally be able to:
- Communicate with Configuration Manager infrastructure
- Receive policy
- Evaluate policy
- Perform inventory
- Perform application operations
- Process software updates
- Report state
- Perform other assigned management functions
Client health is broader than simply checking whether CcmExec is running.
21. Is a running CcmExec service enough to prove the Configuration Manager client is healthy?
Answer:
No.
This is a common interview trap.
You can have:
CcmExec = Running
while the client still has problems with:
- WMI
- Policy processing
- Certificates
- Management Point communication
- BITS
- Inventory
- Software Center
- Local client configuration
Therefore:
A running CcmExec service is necessary in many scenarios, but it is not proof of complete client health.
22. How would you troubleshoot a generally unhealthy Configuration Manager client?
Answer:
I would use a layered approach.
Layer 1 – Service
Get-Service CcmExec
Layer 2 – WMI
Check whether the Configuration Manager client WMI namespace is accessible.
Get-CimInstance -Namespace root\ccm -Class SMS_Client
Layer 3 – Policy
Verify that the client can communicate with the Management Point and receive policy.
Layer 4 – Logs
Review relevant logs such as:
CcmExec.log
LocationServices.log
ClientIDManagerStartup.log
PolicyAgent.log
PolicyEvaluator.log
Layer 5 – Certificates
For HTTPS/PKI scenarios, verify the client certificate and trust chain.
Layer 6 – Repair
Only after identifying the likely cause should you consider:
- Client repair
- WMI repair
- Reinstallation
- Certificate correction
- Network correction
Do not immediately reinstall every unhealthy client.
23. What is Co-Management?
Answer:
Co-management allows Windows devices to be managed concurrently by:
- Configuration Manager
- Microsoft Intune
The device has the Configuration Manager client and is also enrolled into Intune.
The organization can then determine which management workloads remain with Configuration Manager and which are moved to Intune.
Microsoft describes co-management as a way to combine existing Configuration Manager investment with cloud management capabilities.
24. Does enabling Co-Management automatically move all workloads to Intune?
Answer:
No.
This is an important current behavior.
Enabling co-management and moving workloads are separate activities.
Microsoft’s current Cloud Attach experience allows administrators to enable co-management first and then configure workload authority separately.
Therefore:
Enable Co-Management
↓
Device becomes co-managed
↓
Configure Workload Authority
↓
Move selected workloads when ready
Answer:
Workload authority determines whether a particular management workload is primarily handled by Configuration Manager or Intune.
Depending on the current Configuration Manager/Intune capabilities and configuration, workloads can include areas such as:
- Compliance policies
- Windows Update policies
- Resource access
- Endpoint protection
- Client applications
The exact available workload options can change with product releases, so a senior administrator should always verify the options available in the current console.
The important concept is:
Co-management does not mean that both products simultaneously have unrestricted authority over every workload.
26. How would you safely introduce Co-Management into production?
Answer:
I would use a controlled rollout.
Phase 1 – Prerequisites
Verify:
- Supported Windows versions
- Configuration Manager client version
- Intune licensing
- Microsoft Entra configuration
- Intune enrollment configuration
- Network connectivity
- Device identity
- Existing management conflicts
Phase 2 – Pilot
Use a controlled pilot collection.
Phase 3 – Enrollment
Enroll the pilot devices into Intune.
Phase 4 – Validation
Validate:
- Intune enrollment
- Device identity
- Configuration Manager management
- Compliance
- Endpoint security
- Policy behavior
Phase 5 – Workload Migration
Move one workload at a time.
Phase 6 – Expansion
Expand gradually after monitoring results.
This reduces the risk of changing management authority across thousands of devices simultaneously.
27. What is Tenant Attach?
Answer:
Tenant Attach connects a Configuration Manager environment with the Microsoft Intune admin center so Configuration Manager devices can be represented and managed through cloud-based capabilities.
Tenant Attach can provide capabilities such as:
- Device information
- Client details
- Device actions
- CMPivot
- Scripts
- Device timeline
- Resource Explorer
Microsoft specifically distinguishes Tenant Attach from full Co-Management. A Configuration Manager environment can use Tenant Attach without moving management workloads to Intune.
28. What is the difference between Tenant Attach and Co-Management?
Answer:
Tenant Attach
Primarily connects Configuration Manager with the Microsoft Intune admin center and exposes Configuration Manager device information and selected actions.
Co-Management
Allows Windows devices to be managed concurrently by Configuration Manager and Intune, with selected workloads potentially moved to Intune.
Therefore:
Tenant Attach
↓
Cloud visibility + selected cloud actions
Co-Management
↓
Configuration Manager + Intune management
↓
Workload authority can be moved
You can use Tenant Attach without enabling Co-Management.
29. What is Cloud Attach?
Answer:
Cloud Attach is the broader Configuration Manager cloud integration concept.
Microsoft currently describes the primary Cloud Attach capabilities as including:
- Tenant Attach
- Endpoint Analytics
- Co-Management
Cloud Management Gateway is also a related cloud capability used for managing internet-based Configuration Manager clients.
Do not use “Cloud Attach” and “Co-Management” as exact synonyms.
30. Does Tenant Attach mean that Configuration Manager has been replaced by Intune?
Answer:
No.
Tenant Attach does not automatically migrate management from Configuration Manager to Intune.
You can upload Configuration Manager devices to the Intune admin center while continuing to manage those devices through Configuration Manager.
Microsoft explicitly documents that devices can be uploaded without enabling co-management or switching workloads.
31. What is Cloud Management Gateway (CMG)?
Answer:
Cloud Management Gateway is an Azure-hosted Configuration Manager cloud service that allows Configuration Manager clients on the internet to communicate with the Configuration Manager environment.
It is particularly useful for:
- Remote employees
- Internet-based laptops
- Branch offices
- Devices that frequently leave the corporate network
Microsoft’s current architecture deploys CMG as a cloud service in Azure so internet clients can be managed without exposing on-premises Configuration Manager infrastructure directly to the internet.
32. Does CMG require a VPN?
Answer:
No.
One of the major purposes of CMG is to allow Configuration Manager clients to communicate while they are on the internet without requiring a VPN connection back to the corporate network.
However, CMG is not a general-purpose VPN replacement.
It provides Configuration Manager management connectivity, not arbitrary network access to internal applications.
33. Does Co-Management require CMG?
Answer:
No.
Co-management itself does not inherently require CMG.
However, if co-managed devices need Configuration Manager management while they are outside the corporate network, CMG or another supported connectivity method may be required.
Microsoft explicitly states that co-management does not require CMG, while internet-based Configuration Manager clients can use CMG for connectivity.
34. What are the major components involved in a CMG deployment?
Answer:
At a high level, CMG involves:
Configuration Manager Site
|
v
CMG Connection Point
|
v
Azure CMG Service
|
v
Internet-based Configuration Manager Client
Depending on the configuration, client-facing site roles such as the Management Point and Software Update Point are configured to support CMG traffic.
Microsoft’s current setup process includes deploying the CMG service, adding the CMG connection point and configuring the site and site roles for the service.
35. A remote client cannot communicate with Configuration Manager through CMG. What would you check?
Answer:
I would troubleshoot in this order:
1. Client identity
Confirm the device is a valid Configuration Manager client.
2. Internet connectivity
Verify normal internet access.
3. Client configuration
Verify the client knows about the CMG.
4. CMG health
Check the CMG deployment and status in the Configuration Manager console.
5. CMG Connection Point
Verify communication between the on-premises site and the CMG service.
6. Management Point
Confirm that the configured Management Point supports CMG traffic.
7. Certificates/authentication
If certificate-based authentication is being used, verify certificate validity and trust.
8. Logs
Review the relevant client and server-side CMG logs.
Do not immediately rebuild the CMG. First determine which layer is failing.
36. Can CMG be used for application content?
Answer:
CMG is primarily a management connectivity mechanism, but Configuration Manager supports scenarios where CMG-related cloud content capabilities can be configured.
Do not state that:
“CMG is automatically a normal Distribution Point.”
That is incorrect.
Content distribution through CMG depends on the configured architecture and supported content configuration.
When troubleshooting an application over the internet, separately verify:
Management connectivity
+
Content location
+
Content availability
A client can have healthy CMG management communication and still fail to obtain application content.
37. What is the difference between CMG and traditional Internet-Based Client Management (IBCM)?
Answer:
Both can provide Configuration Manager management for internet-based clients, but their architectures differ.
CMG
Uses Azure-hosted cloud infrastructure and is Microsoft’s modern cloud-oriented approach for internet-based Configuration Manager management.
IBCM
Uses internet-facing Configuration Manager infrastructure and traditionally requires exposing appropriate site roles through the organization’s internet-facing architecture.
For a modern environment, CMG is often considered when designing cloud-based internet client management, while existing environments may still use IBCM.
The important interview point is to understand that they are different architectures, not two names for the same feature.
38. What is a Boundary Group’s role for an internet-based client?
Answer:
Boundary Groups help Configuration Manager determine appropriate site-system locations and content locations for clients.
They are important for determining things such as:
- Site assignment
- Management Point location
- Software Update Point location
- Distribution Point/content location
However, do not simplify the concept to:
“The boundary directly tells the client which server to use.”
Actual behavior depends on the boundary group configuration, relationships and fallback configuration.
When troubleshooting a remote client, verify its current boundary group and the site systems associated with that boundary group.
39. How can you troubleshoot a client that has the wrong Boundary Group?
Answer:
First determine the client’s actual network identity.
Check:
- IP address
- Subnet
- AD site where applicable
- VPN address
- Boundary definitions
- Boundary group membership
- Boundary group relationships
- Site assignment
- Current Management Point
In a tenant-attached environment, current client information can also be viewed through the Microsoft Intune admin center, including boundary group membership.
The important point is:
Don’t change boundaries until you understand what network identity the client is actually presenting.
40. What is the relationship between Configuration Manager and SQL Server?
Answer:
The Configuration Manager site database stores the site’s management data.
SQL Server is therefore a critical infrastructure dependency.
Configuration Manager uses the site database for information such as:
- Devices
- Collections
- Deployments
- Inventory
- Configuration information
- Software update information
- Compliance data
- Site configuration
If SQL becomes unavailable, many Configuration Manager administrative and processing functions can be affected.
However, this does not mean that all existing client activity immediately stops. Clients may continue performing some locally cached or previously received operations depending on the situation.
41. How would you troubleshoot a Configuration Manager SQL/database issue?
Answer:
I would separate the problem into layers.
Layer 1 – SQL Service
Verify the SQL Server service is running.
Layer 2 – Connectivity
Verify that the Configuration Manager site server can communicate with SQL.
Layer 3 – Database
Check:
- Database availability
- Disk space
- Transaction log growth
- Database health
- SQL errors
Layer 4 – Configuration Manager
Review relevant site component and database-related logs.
Layer 5 – Reporting
If only reports are failing, separately investigate SSRS/reporting services rather than assuming the site database itself is down.
Never directly modify Configuration Manager database tables as a troubleshooting shortcut unless using a Microsoft-supported procedure.
42. What is the Reporting Services Point?
Answer:
The Reporting Services Point integrates Configuration Manager with SQL Server Reporting Services (SSRS) for Configuration Manager reporting.
It allows administrators to use reports for information such as:
- Hardware inventory
- Software inventory
- Compliance
- Deployments
- Software updates
- Client information
If Configuration Manager itself is working but reports are failing, investigate the reporting layer separately:
Configuration Manager
|
v
Site Database
|
v
SSRS / Reporting Services Point
|
v
Reports
43. A Configuration Manager console shows current inventory, but a report shows old data. What would you investigate?
Answer:
I would first determine whether the problem is:
- Inventory collection
- Site database processing
- Reporting data
- SSRS
- Report query/filtering
- Report execution/cache behavior
If the console itself shows current information but the report does not, I would not immediately troubleshoot the client.
Instead, I would compare:
Client Inventory
↓
Site Database
↓
Report Query
↓
SSRS
This helps isolate the layer where the stale information appears.
44. A large number of clients suddenly stop reporting Hardware Inventory. What is your troubleshooting approach?
Answer:
Because many clients are affected simultaneously, I would first suspect a shared dependency rather than individual client failures.
I would check:
Client side
- Whether inventory cycles are occurring
InventoryAgent.log
Network
- Management Point connectivity
- Firewall changes
- DNS
- Certificates if applicable
Management Point
- MP health
- IIS/application errors
- Site component status
Site Server
- Inventory processing
- Site component errors
- Disk space
SQL
- Database availability
- SQL connectivity
- Database/log disk space
The pattern is important:
One client failing usually suggests a client-specific issue; thousands failing simultaneously suggests a shared infrastructure or policy problem.
45. A Configuration Baseline suddenly reports thousands of devices as non-compliant. What would you do?
Answer:
I would not immediately remediate all devices.
First determine whether the compliance result is genuine.
Step 1
Identify the exact Configuration Item reporting non-compliance.
Step 2
Compare:
Expected value
vs.
Actual value
Step 3
Check whether the Configuration Item was recently modified.
Step 4
Check whether Client Settings or policy changed.
Step 5
Validate the discovery method.
For example, a registry-based CI may be failing because:
- Registry path changed
- Value type changed
- 32-bit/64-bit registry location differs
- Detection script has an error
Step 6
Test against a small number of machines.
Only after confirming the baseline is correct should remediation be considered.
46. A device is both managed by Configuration Manager and Intune, but policies conflict. How would you troubleshoot it?
Answer:
This is a classic Co-Management scenario.
I would first identify which workload owns the setting.
Then determine:
- Is the device actually co-managed?
- Which workload is assigned to Configuration Manager?
- Which workload is assigned to Intune?
- Are both platforms configuring the same setting?
- Is there a conflict between Configuration Manager policy and Intune policy?
- Is the device in a pilot collection?
- Are multiple Intune policies targeting the device?
- Are Configuration Manager Client Settings also affecting the device?
The key principle is:
Do not troubleshoot the setting before determining which management authority is supposed to control it.
Microsoft’s co-management model explicitly allows workload authority to be controlled separately.
47. A device appears in Configuration Manager but not in the Intune admin center. What could be wrong?
Answer:
If Tenant Attach is expected, I would check:
Configuration Manager
- Tenant Attach configuration
- Device upload configuration
- Client health
- Device eligibility
- Site connectivity
Microsoft Entra / Cloud
- Tenant configuration
- Authentication
- Application/service principal
- Required permissions
- Synchronization
Device
- Configuration Manager client health
- Internet connectivity
- Policy
Scope
Confirm that the device is actually included in the configured upload scope.
Tenant Attach uploads Configuration Manager device information to the Intune admin center; it does not mean every Configuration Manager resource is automatically represented regardless of configuration.
48. A co-managed device fails to enroll into Intune. What would you investigate?
Answer:
I would check the complete enrollment chain.
1. Device identity
Verify the expected Microsoft Entra device state.
2. Duplicate device records
Microsoft specifically recommends identifying and cleaning up duplicate Microsoft Entra device objects before attempting co-management auto-enrollment because duplicate records can cause enrollment problems.
3. Intune enrollment configuration
Check:
- Automatic enrollment
- Enrollment restrictions
- Licensing
- MDM scope/configuration
4. Configuration Manager
Verify:
- Client health
- Co-management eligibility
- Policy
- Cloud Attach configuration
5. Network
Verify access to required Microsoft cloud endpoints.
6. Device logs
Review Windows MDM/enrollment and Configuration Manager logs.
The important approach is to determine whether the failure occurs during:
Device Identity
↓
Eligibility
↓
Intune Enrollment
↓
Policy
49. A company wants to modernize Configuration Manager without immediately abandoning it. What architecture would you propose?
Answer:
I would avoid treating modernization as a “Configuration Manager versus Intune” decision.
A practical architecture can use:
Configuration Manager
|
+---- Existing software deployment
|
+---- Existing OSD
|
+---- Existing patching
|
+---- Existing infrastructure
|
v
Cloud Attach
|
+---- Tenant Attach
|
+---- Co-Management
|
+---- Endpoint Analytics
|
+---- CMG
|
v
Microsoft Intune
The organization can then decide which workloads should remain under Configuration Manager and which should move to Intune.
This allows a gradual transition rather than an unnecessary “big bang” migration.
Microsoft describes Cloud Attach specifically as a way to extend an existing Configuration Manager environment with cloud capabilities while minimizing disruption.
50. How would you approach a complex Configuration Manager production incident from start to finish?
Answer:
This is one of the most important senior-level interview questions.
I would use a structured troubleshooting methodology.
Step 1 – Define the symptom
For example:
“5,000 clients have stopped reporting inventory.”
Do not begin changing configuration before defining the exact symptom.
Step 2 – Determine the scope
Ask:
- One device?
- One collection?
- One site?
- One subnet?
- One boundary group?
- All clients?
- Internet clients only?
- Co-managed clients only?
Scope immediately reduces the troubleshooting area.
Step 3 – Determine what changed
Check:
- Configuration Manager changes
- Client Settings
- Boundary changes
- Firewall changes
- DNS changes
- Certificate changes
- Intune/Co-Management changes
- Windows updates
- SQL changes
- Network changes
Step 4 – Follow the management flow
For a client operation, think:
Client
↓
Network
↓
Management Point
↓
Policy
↓
Site Processing
↓
Database
↓
Reporting / Console
For content:
Client
↓
Content Location
↓
Distribution Point / Supported Cloud Content Location
↓
Content Transfer
↓
Installation
For Co-Management:
Configuration Manager
↓
Cloud Attach
↓
Microsoft Entra / Intune
↓
Enrollment
↓
Workload Authority
↓
Intune Policy
For CMG:
Internet Client
↓
CMG
↓
CMG Connection Point
↓
Configuration Manager Site
↓
Management Point / SUP / Other Supported Roles
Step 5 – Check logs at the failing layer
Do not collect every log in the environment.
Start with the log that corresponds to the failed operation.
Examples:
PolicyAgent.log
PolicyEvaluator.log
LocationServices.log
InventoryAgent.log
CIAgent.log
DCMAgent.log
AppDiscovery.log
AppEnforce.log
WUAHandler.log
SMSTS.log
Step 6 – Reproduce with a controlled client
If thousands of clients are affected, select a representative test device.
Determine whether the same failure occurs.
Step 7 – Fix the root cause
Avoid actions such as:
- Reinstalling every client
- Rebuilding the Management Point
- Recreating boundaries
- Recreating deployments
- Rebuilding the site
unless evidence supports those actions.
Step 8 – Validate
After the fix:
- Test a single client
- Test a small collection
- Monitor site health
- Confirm database/reporting results
- Expand gradually
Real-World Senior Configuration Manager Scenarios
Scenario 1 – Hardware Inventory is stale for every laptop
Investigation
InventoryAgent.log
↓
Client Settings
↓
Management Point
↓
Inventory Processing
↓
SQL
If all clients stopped reporting simultaneously, investigate shared infrastructure first.
Scenario 2 – Compliance suddenly drops from 95% to 20%
Do not immediately remediate.
Check:
- Which CI changed?
- Was the baseline modified?
- Did the discovery method change?
- Did a Windows update change the expected value?
- Is the compliance result actually correct?
Scenario 3 – Co-managed devices receive conflicting policies
First identify workload authority.
Who owns the workload?
|
+---- Configuration Manager
|
+---- Intune
Then investigate policy conflicts within the platform that owns the workload.
Scenario 4 – Remote users cannot receive Configuration Manager policy
Check:
Internet
↓
Client
↓
CMG configuration
↓
CMG health
↓
CMG Connection Point
↓
Management Point
Do not immediately assume that the client needs a VPN.
Scenario 5 – Tenant Attach works for most devices but not a collection
Check:
- Upload scope
- Collection membership
- Client status
- Cloud Attach configuration
- Device eligibility
- Synchronization
- Client connectivity
Tenant Attach does not automatically imply that every resource is uploaded under every configuration.
Configuration Manager Senior Troubleshooting Decision Tree
START
|
v
What failed?
|
+----------+----------+
| | |
Policy Inventory Content
| | |
v v v
MP? Client? DP?
| | |
v v v
Network? Inventory Boundary
| Agent? Group?
| | |
v v v
Policy MP/Site Content
Logs Processing Availability
|
v
SQL?
|
v
Reporting?
For cloud-managed scenarios:
Internet Device
|
+---- CMG?
|
+---- Tenant Attach?
|
+---- Co-Management?
|
+---- Intune Enrollment?
|
v
Identify the exact failing layer
Important Configuration Manager Commands
Check Configuration Manager Client Service
Get-Service CcmExec
Check Configuration Manager Client WMI
Get-CimInstance -Namespace root\ccm -Class SMS_Client
Check BITS Service
Get-Service BITS
Check Windows Update Service
Get-Service wuauserv
Check Network Configuration
ipconfig /all
Check DNS
nslookup <server-name>
Check Routing
route print
Check connectivity to a server
Test-NetConnection <server-name> -Port 443
Use the appropriate port for the specific service being tested rather than assuming every Configuration Manager communication uses the same port.
Important Configuration Manager Logs – Quick Reference
| Area | Important Logs |
|---|---|
| Client health | CcmExec.log |
| Client identity | ClientIDManagerStartup.log |
| Management Point/location | LocationServices.log |
| Policy | PolicyAgent.log |
| Policy evaluation | PolicyEvaluator.log |
| Hardware Inventory | InventoryAgent.log |
| Application discovery | AppDiscovery.log |
| Application installation | AppEnforce.log |
| Software Updates | WUAHandler.log |
| Update deployment | UpdatesDeployment.log |
| Content | ContentTransferManager.log, DataTransferService.log |
| OSD | SMSTS.log |
| Compliance | CIAgent.log, DCMAgent.log, DCMReporting.log |
Quick Revision – Day 9 Part 5
Inventory
- Hardware Inventory collects hardware/configuration information.
- Software Inventory collects configured file information.
- Inventory data is different from Discovery Data Records.
InventoryAgent.logis an important client-side inventory log.- Avoid collecting unnecessary inventory data.
Compliance
- Configuration Item = individual configuration requirement.
- Configuration Baseline = collection of Configuration Items.
- Compliance evaluates whether devices meet defined requirements.
- Remediation should be tested before production rollout.
Client Health
CcmExecrunning does not prove complete client health.- Check WMI, policy, network, certificates and relevant logs.
- Repair the actual failing component instead of blindly reinstalling the client.
Co-Management
- Configuration Manager + Intune can manage the same Windows device.
- Workload authority can be controlled.
- Enabling co-management does not automatically mean all workloads move to Intune.
- Pilot before moving production workloads.
Tenant Attach
- Provides Configuration Manager device information and selected actions through the Intune admin center.
- Does not automatically migrate workloads to Intune.
- Can be used without Co-Management.
Cloud Attach
- Broader cloud integration for Configuration Manager.
- Includes capabilities such as Tenant Attach, Endpoint Analytics and Co-Management.
CMG
- Azure-hosted Configuration Manager management service.
- Designed for internet-based Configuration Manager clients.
- Does not require a VPN for its intended management connectivity.
- Does not provide general-purpose VPN connectivity.
- CMG and Co-Management are not the same thing.
Production Troubleshooting
Always determine:
What failed?
↓
Who is affected?
↓
What changed?
↓
Which layer failed?
↓
Which log proves it?
↓
What is the smallest safe fix?
↓
How will I validate it?
Exam Answer Summary
Q: What is Hardware Inventory?
Hardware Inventory collects hardware and configuration information from Configuration Manager clients and stores the processed information in the site database.
Q: What is a Configuration Item?
A Configuration Item defines a configuration requirement that Configuration Manager can evaluate.
Q: What is a Configuration Baseline?
A Configuration Baseline is a collection of Configuration Items evaluated together for compliance.
Q: What is Co-Management?
Co-management allows Windows devices to be managed concurrently by Configuration Manager and Intune, with selected workloads potentially moved to Intune.
Q: What is Tenant Attach?
Tenant Attach connects Configuration Manager with the Microsoft Intune admin center and provides cloud-based visibility and selected actions for Configuration Manager devices.
Q: What is Cloud Attach?
Cloud Attach is the broader approach for connecting Configuration Manager capabilities with cloud services such as Tenant Attach, Endpoint Analytics and Co-Management.
Q: What is CMG?
Cloud Management Gateway is an Azure-hosted Configuration Manager service that enables management of Configuration Manager clients over the internet without requiring direct exposure of on-premises Configuration Manager infrastructure.
Q: What is your approach to a production Configuration Manager incident?
I first determine the exact symptom and scope, identify what changed, isolate the failing layer, review the relevant logs, reproduce the problem with a controlled client, apply the smallest safe fix and validate the result before expanding the change.
Senior Interview Tip
For a senior Configuration Manager interview, avoid answers such as:
“I would reinstall the client.”
or:
“I would restart the server.”
Those are actions, not troubleshooting methodologies.
A stronger senior-level answer is:
“First I would determine the scope and identify whether the failure is client-side, network-related, Management Point-related, site-processing-related, database-related or cloud-related. I would then use the appropriate Configuration Manager logs to prove where the failure occurs before making a targeted change.”
That demonstrates structured troubleshooting rather than trial-and-error administration.
Day 9 – Microsoft Configuration Manager: Complete
You have now completed all five planned parts of Day 9:
- Part 1 – Architecture, Site Components, Clients & Core Administration
- Part 2 – Application Deployment, Content Distribution & Software Center Troubleshooting
- Part 3 – Software Updates, WSUS, SUP, ADRs & Patch Management
- Part 4 – Operating System Deployment, Task Sequences, PXE, WinPE & OSD Troubleshooting
- Part 5 – Advanced Troubleshooting, Inventory, Compliance, Co-Management, Cloud Attach & Production Scenarios
This completes the planned Microsoft Configuration Manager/SCCM/MECM interview module without repeating the major concepts already covered in Parts 1–4.
