<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: System Center Mobile Device Manager 2008 &#8211; Install Guide (No Gateway) &#8211; Part 3</title>
	<atom:link href="http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/feed/" rel="self" type="application/rss+xml" />
	<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/</link>
	<description>place of the mobility way</description>
	<lastBuildDate>Fri, 10 Feb 2012 08:29:06 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-15778</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Tue, 20 Jul 2010 14:54:04 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-15778</guid>
		<description>The iPhone will not work, so don&#039;t spend any more time on that :) You will not be able to enroll via the web page either - that&#039;s just used for test purposes and a simple &quot;instruction&quot; to the web service. To enroll a device you will need the domain enroll feature, which is only available on WM 6.1/6.5. If you&#039;re using the Windows Mobile emulator and can&#039;t see this icon check with OS version you are using. If it&#039;s WM 6.0 or earlier it is not present.</description>
		<content:encoded><![CDATA[<p>The iPhone will not work, so don&#8217;t spend any more time on that <img src='http://mobilitydojo.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  You will not be able to enroll via the web page either &#8211; that&#8217;s just used for test purposes and a simple &#8220;instruction&#8221; to the web service. To enroll a device you will need the domain enroll feature, which is only available on WM 6.1/6.5. If you&#8217;re using the Windows Mobile emulator and can&#8217;t see this icon check with OS version you are using. If it&#8217;s WM 6.0 or earlier it is not present.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-15735</link>
		<dc:creator>James</dc:creator>
		<pubDate>Mon, 19 Jul 2010 21:50:37 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-15735</guid>
		<description>As a followup, I followed the guide on technet you posted  

Andreas 
Mar 12th, 2009 at 5:06 pm 
I’d follow the steps in this article: . Start out with the “Unable to Enroll Device in Domain” section.

with no luck.  I am still holding out hope this can be done with a iPhone becuase I get the same website on my windows mobile emulated device that I do from a web brower on my iphone.</description>
		<content:encoded><![CDATA[<p>As a followup, I followed the guide on technet you posted  </p>
<p>Andreas<br />
Mar 12th, 2009 at 5:06 pm<br />
I’d follow the steps in this article: . Start out with the “Unable to Enroll Device in Domain” section.</p>
<p>with no luck.  I am still holding out hope this can be done with a iPhone becuase I get the same website on my windows mobile emulated device that I do from a web brower on my iphone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-15734</link>
		<dc:creator>James</dc:creator>
		<pubDate>Mon, 19 Jul 2010 21:46:16 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-15734</guid>
		<description>I am trying to connect a iPhone to the MDM (while this may not work) when I run the device emulator for a windows mobile phone I do not seem to have the &quot;domain enroll&quot; in the settings of my device.  When I try and put the server address in manually I get the iis website, but it never has a box or anything that pops up wanting a un and pw.  It looks to be more of the &quot;test&quot; site with &quot;shouldenroll&quot; links and &quot;enroll&quot; links etc.  I am sure you guys know the one.  What am I missing?  Do I have to use the domain enroll feature?  The MDM  sends me the email etc.  It seems like to me I am just missing one step somewhere ... any help still out there?  Thanks James</description>
		<content:encoded><![CDATA[<p>I am trying to connect a iPhone to the MDM (while this may not work) when I run the device emulator for a windows mobile phone I do not seem to have the &#8220;domain enroll&#8221; in the settings of my device.  When I try and put the server address in manually I get the iis website, but it never has a box or anything that pops up wanting a un and pw.  It looks to be more of the &#8220;test&#8221; site with &#8220;shouldenroll&#8221; links and &#8220;enroll&#8221; links etc.  I am sure you guys know the one.  What am I missing?  Do I have to use the domain enroll feature?  The MDM  sends me the email etc.  It seems like to me I am just missing one step somewhere &#8230; any help still out there?  Thanks James</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-7895</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Fri, 18 Dec 2009 20:45:09 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-7895</guid>
		<description>I&#039;ve posted a reply over at the TechNet SCMDM forums:
http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/262dfe22-e334-42a4-afc8-de82fcd8c650</description>
		<content:encoded><![CDATA[<p>I&#8217;ve posted a reply over at the TechNet SCMDM forums:<br />
<a href="http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/262dfe22-e334-42a4-afc8-de82fcd8c650" rel="nofollow">http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/262dfe22-e334-42a4-afc8-de82fcd8c650</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Isaac</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-7884</link>
		<dc:creator>Isaac</dc:creator>
		<pubDate>Fri, 18 Dec 2009 07:52:01 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-7884</guid>
		<description>Hi Andreas,

I have followed through all the steps but I seems to be having a problem connecting to the enrollment server from the mobile emulator. I came across a tool called EM IP Utility, installed it on the emulator and scaned it for assigned IP but the IP assigned to it is wrong. I have enabled the NE2000 PCMCIA network adapter and bind it to the VMWare Accelerated AMD PCNet Adapter.

Any reason why the emulator is not picking the IP address assigned to the server?

Assigned IP is 192.168.55.101
Expected IP is 192.168.10.xxx</description>
		<content:encoded><![CDATA[<p>Hi Andreas,</p>
<p>I have followed through all the steps but I seems to be having a problem connecting to the enrollment server from the mobile emulator. I came across a tool called EM IP Utility, installed it on the emulator and scaned it for assigned IP but the IP assigned to it is wrong. I have enabled the NE2000 PCMCIA network adapter and bind it to the VMWare Accelerated AMD PCNet Adapter.</p>
<p>Any reason why the emulator is not picking the IP address assigned to the server?</p>
<p>Assigned IP is 192.168.55.101<br />
Expected IP is 192.168.10.xxx</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-7356</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Thu, 26 Nov 2009 16:47:47 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-7356</guid>
		<description>Hold on, you&#039;re nearly there by now - it&#039;s no fun if you don&#039;t run into a couple of obstacles along the way :)

When it fails during enrollment with an error like this the steps you should check are:
- You have a valid SSL certificate for the enrollment site. (Should be fixed during install but you never know.)
- If you don&#039;t use mobileenroll.contoso.com as the address you will need to type it in manually on the device.
- The certificate will be checked so if you type in 192.168.x.y it will fail if the certificate isn&#039;t issued to this name.
- Are you using multiple domain names and e-mail addresses? Always test using the primary address if you&#039;re having problems.

Still no go? You could test the webservices on a desktop to see if you are eligible for enrollment.</description>
		<content:encoded><![CDATA[<p>Hold on, you&#8217;re nearly there by now &#8211; it&#8217;s no fun if you don&#8217;t run into a couple of obstacles along the way <img src='http://mobilitydojo.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>When it fails during enrollment with an error like this the steps you should check are:<br />
- You have a valid SSL certificate for the enrollment site. (Should be fixed during install but you never know.)<br />
- If you don&#8217;t use mobileenroll.contoso.com as the address you will need to type it in manually on the device.<br />
- The certificate will be checked so if you type in 192.168.x.y it will fail if the certificate isn&#8217;t issued to this name.<br />
- Are you using multiple domain names and e-mail addresses? Always test using the primary address if you&#8217;re having problems.</p>
<p>Still no go? You could test the webservices on a desktop to see if you are eligible for enrollment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael B. Abbott</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-7346</link>
		<dc:creator>Michael B. Abbott</dc:creator>
		<pubDate>Thu, 26 Nov 2009 06:34:16 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-7346</guid>
		<description>Well seems I missed a step in a technet article in while you linked to, heh.. I&#039;m up and going; however, I am unable to get my phone (Touch Pro 2) to enroll.  I&#039;ve entered the credentials as per the pre-enrollment wizard, but get:

&quot;We are unable to localte a server successfully, but enrollment could not complete.  Verify your e-mail address and enrollment password, and then try again.&quot;

I&#039;ve entered the information correctly..</description>
		<content:encoded><![CDATA[<p>Well seems I missed a step in a technet article in while you linked to, heh.. I&#8217;m up and going; however, I am unable to get my phone (Touch Pro 2) to enroll.  I&#8217;ve entered the credentials as per the pre-enrollment wizard, but get:</p>
<p>&#8220;We are unable to localte a server successfully, but enrollment could not complete.  Verify your e-mail address and enrollment password, and then try again.&#8221;</p>
<p>I&#8217;ve entered the information correctly..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael B. Abbott</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-7345</link>
		<dc:creator>Michael B. Abbott</dc:creator>
		<pubDate>Thu, 26 Nov 2009 05:17:55 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-7345</guid>
		<description>I&#039;ve run into a snag that despite putting a substantial effort into searching through on-line and performing some tasks suggested therein, I&#039;ve been unable to resolve.  Any pointers of where to look would be appreciated.

When I go to enroll a device I receive the following:

Summary: 1 item(s). 0 succeeded, 1 failed. 
Elapsed time: 00:00:00


Enrollment Data
Failed

Error:
You are not authorized to perform this action.

Mobile Device Manager Shell command attempted:
New-EnrollmentRequest -Owner &#039;CN=Domain Username Removed,CN=Users,DC=domainname,DC=ca&#039; -Name &#039;TouchPro2&#039; -Container &#039;OU=SCMDM Managed Devices (ALLSOL),DC=domainname,DC=ca&#039;

Elapsed Time: 00:00:00

---

BPA comes back with 4 warnings that are performance related (I&#039;m setting the servers up in VMWware (SCMDM = 2003 x64 Enterprise / Cert Server on Server 2003 x86) such as low ram, disk space, and processor speed. Everything else has green checkmarks.

I&#039;m running MDM Console as Aministrator and have ensured that account is part of the 5 crucial SCMDM groups and Domain Admins.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve run into a snag that despite putting a substantial effort into searching through on-line and performing some tasks suggested therein, I&#8217;ve been unable to resolve.  Any pointers of where to look would be appreciated.</p>
<p>When I go to enroll a device I receive the following:</p>
<p>Summary: 1 item(s). 0 succeeded, 1 failed.<br />
Elapsed time: 00:00:00</p>
<p>Enrollment Data<br />
Failed</p>
<p>Error:<br />
You are not authorized to perform this action.</p>
<p>Mobile Device Manager Shell command attempted:<br />
New-EnrollmentRequest -Owner &#8216;CN=Domain Username Removed,CN=Users,DC=domainname,DC=ca&#8217; -Name &#8216;TouchPro2&#8242; -Container &#8216;OU=SCMDM Managed Devices (ALLSOL),DC=domainname,DC=ca&#8217;</p>
<p>Elapsed Time: 00:00:00</p>
<p>&#8212;</p>
<p>BPA comes back with 4 warnings that are performance related (I&#8217;m setting the servers up in VMWware (SCMDM = 2003 x64 Enterprise / Cert Server on Server 2003 x86) such as low ram, disk space, and processor speed. Everything else has green checkmarks.</p>
<p>I&#8217;m running MDM Console as Aministrator and have ensured that account is part of the 5 crucial SCMDM groups and Domain Admins.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Larry</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-6117</link>
		<dc:creator>Larry</dc:creator>
		<pubDate>Thu, 08 Oct 2009 19:07:24 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-6117</guid>
		<description>Thanks for the reply. I&#039;ve been pulled into another project. I&#039;ll get back to MDM in a couple weeks, I hope.</description>
		<content:encoded><![CDATA[<p>Thanks for the reply. I&#8217;ve been pulled into another project. I&#8217;ll get back to MDM in a couple weeks, I hope.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-5989</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Thu, 01 Oct 2009 18:10:41 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-5989</guid>
		<description>The AD error regarding the portalurl not being created sounds like it&#039;s related to the self service portal although I have not seen that error before. (In MDM SP1 the portal is included by default, wheras in RTM it was an optional download.) While this might mean that the SSP is not working it should not affect the enrollment.

Provided you aren&#039;t trying to run them both on port 443 or a similar conflict. The SSP can be run on a different port, but the enrollment site needs to run on port 443 for devices to be able to enroll. Port 8445 is for the admin part of it, and it is correct that some of the web service methods can only be run from localhost. I have another post detailing how the web services work, and how they can be used.

Are you running multiple MDM roles on a single box (like in my test scenario) or have you split the roles over different boxes? Are you running the DC and MDM on the same server? This may create access issues. I cannot remember any issues using the domain admin account for administrating the MDM servers as long as this account is also a member of the MDM groups. (Remember to logout and login for the membership to apply.) I usually attempt device enrollment with a normal user account though.

If I were to troubleshoot the issue I&#039;d have a crack at the following steps:
- Check Event Viewer for any suspicious error messages.
- Check that you have the correct DNS entries. Records for mobileenroll, for the SSP, for MDM, etc. You can have multiple records pointing to the same IP address.
- Double check that certificates are installed, and are valid.
- Check IIS that the host names apply to the correct web site, the correct ports, and that there are no conflicts in the IIS setup.

If all is good you could attempt a repair install of the enrollment role.</description>
		<content:encoded><![CDATA[<p>The AD error regarding the portalurl not being created sounds like it&#8217;s related to the self service portal although I have not seen that error before. (In MDM SP1 the portal is included by default, wheras in RTM it was an optional download.) While this might mean that the SSP is not working it should not affect the enrollment.</p>
<p>Provided you aren&#8217;t trying to run them both on port 443 or a similar conflict. The SSP can be run on a different port, but the enrollment site needs to run on port 443 for devices to be able to enroll. Port 8445 is for the admin part of it, and it is correct that some of the web service methods can only be run from localhost. I have another post detailing how the web services work, and how they can be used.</p>
<p>Are you running multiple MDM roles on a single box (like in my test scenario) or have you split the roles over different boxes? Are you running the DC and MDM on the same server? This may create access issues. I cannot remember any issues using the domain admin account for administrating the MDM servers as long as this account is also a member of the MDM groups. (Remember to logout and login for the membership to apply.) I usually attempt device enrollment with a normal user account though.</p>
<p>If I were to troubleshoot the issue I&#8217;d have a crack at the following steps:<br />
- Check Event Viewer for any suspicious error messages.<br />
- Check that you have the correct DNS entries. Records for mobileenroll, for the SSP, for MDM, etc. You can have multiple records pointing to the same IP address.<br />
- Double check that certificates are installed, and are valid.<br />
- Check IIS that the host names apply to the correct web site, the correct ports, and that there are no conflicts in the IIS setup.</p>
<p>If all is good you could attempt a repair install of the enrollment role.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

