|
Requirement
|
Owner
|
Complete
|
|---|
|
Configure the MDM Active Directory domain by running ADConfig /createinstance:<instance name> /Domain:<domain name> for the domain in which you will install MDM 2008 SP1. You must first run this configuration in the domain in which you will install MDM 2008 SP1. This step requires administrator domain and network credentials.
|
Domain Administrator
|
[ ]
|
|
Create the MDM 2008 SP1 certificate templates by running ADConfig /createtemplates:<instance name>. This requires elevated domain and network credentials.
|
Enterprise Administrator
|
[ ]
|
|
Enable the MDM 2008 SP1 certificate templates by running ADConfig.exe /enableTemplates:<instance name> /ca:<ca_server_fqdn>\<ca_instance_name>. This requires elevated domain and network credentials.
|
Certification Authority Credentials
Enterprise Administrator Credentials
|
[ ]
|
|
Configure the MDM Group Policy security settings by running ADConfig /enablegpsecurity:<instance name> with the appropriate options. This requires elevated domain and network credentials, or you must grant appropriate credentials to every server that is running MDM in Group Policy objects.
|
Domain Administrator or Schema Administrator (depends on options chosen)
|
[ ]
|
|
Add administrator users to the SCMDMServerAdministrators group. This enables MDM 2008 SP1 Server Administrators to install MDM components and administer the installation for other users.
|
Domain Administrator
|
[ ]
|
|
Create additional organizational units (OUs) for managed devices and delegate MDM Enrollment Server permissions to the OUs. (This step is optional.)
|
Domain Administrator
|
[ ] Optional
|
|
Make sure that you grant permissions on the domain certification authority to revoke a managed device enrollment. If you configured it manually, you must do this by using the server that is running the certification authority.
|
Certification Authority Administrator
|
[ ]
|
|
If you have Exchange Server 2007 with SP1 installed, run the Set-ActiveSyncMailboxPolicy cmdlet to enable managed devices to access the Exchange Client Access Server.
|
Exchange Administrator
|
[ ]
|
|
Back up the IIS metabase for every server in which you are installing MDM. This includes MDM Device Management Server, MDM Enrollment Server, and MDM Gateway Server. For more information, see "Back Up and Restore the IIS Metabase (IIS 6.0)" at this Microsoft Web page: http://go.microsoft.com/fwlink/?LinkId=103605.
|
MDM Server Administrator
|
[ ]
|
|
Set IIS to allow x64-bit applications to run on every server that is running MDM Device Management Server, MDM Enrollment Server, and MDM Gateway Server. For more information, see "Set IIS to Allow x64-bit Applications" in Install and Configure IIS for MDM.
|
MDM Server Administrator
|
[ ]
|
|
Install MDM Enrollment Server. On the MDM 2008 SP1 installation CD, on the Setup menu, select Install and then select Enrollment Server. Make sure that you specify the load balancer FQDNs if you are using a load balancer.
Important You must follow the steps in the MDM Deployment Guide to complete this task. This is required.
|
MDM Server Administrator. Must be a member of local Administrators group on the server.
|
[ ]
|
|
Install MDM Device Management Server. On the installation disk for MDM 2008 SP1, on the Setup menu, select Install and then select Mobile Device Management Server. Make sure that you specify the load balancer FQDNs if you are using a load balancer.
Important You must follow the steps in the MDM Deployment Guide to complete this task. This is required.
|
MDM Server Administrator. Must be a member of local Administrators group on the server.
|
[ ]
|
|
Install Administrator Tools. On the installation disk for MDM 2008 SP1, select Administrator Tools. You can install MDM Administrator Tools on any domain-joined server that meets MDM prerequisites.
Important You must follow the steps in the MDM Deployment Guide to complete this task. This is required.
|
Member of local Administrators group on the server. MDM Server Administrator not required
|
[ ]
|
|
Obtain the MDM Gateway Server certificate for MDM Gateway Server before installation. See the MDM Deployment Guide.
|
MDM Server Administrator
|
[ ]
|
|
The certificate chain and root certificate for the certification authorities in your MDM system are transferred in a security-enhanced way and imported to the appropriate store on the server that is running MDM Gateway Server. See Step 5: Installing MDM Gateway Server in the MDM Deployment Guide.
|
MDM Server Administrator
|
[ ]
|
|
Install MDM Gateway Server.
Important You must follow the steps in Step 5: Installing MDM Gateway Server to complete this task. This is required.
|
Member of local Administrators group on the server. MDM Server Administrator recommended.
|
[ ]
|