<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: System Center Mobile Device Manager 2008 &#8211; Install Guide (No Gateway) &#8211; Part 3</title>
	<atom:link href="http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/feed/" rel="self" type="application/rss+xml" />
	<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/</link>
	<description>place of the mobility way</description>
	<lastBuildDate>Fri, 26 Feb 2010 11:18:02 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-7895</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Fri, 18 Dec 2009 20:45:09 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-7895</guid>
		<description>I&#039;ve posted a reply over at the TechNet SCMDM forums:
http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/262dfe22-e334-42a4-afc8-de82fcd8c650</description>
		<content:encoded><![CDATA[<p>I&#8217;ve posted a reply over at the TechNet SCMDM forums:<br />
<a href="http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/262dfe22-e334-42a4-afc8-de82fcd8c650" rel="nofollow">http://social.technet.microsoft.com/Forums/en-US/SCMDM/thread/262dfe22-e334-42a4-afc8-de82fcd8c650</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Isaac</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-7884</link>
		<dc:creator>Isaac</dc:creator>
		<pubDate>Fri, 18 Dec 2009 07:52:01 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-7884</guid>
		<description>Hi Andreas,

I have followed through all the steps but I seems to be having a problem connecting to the enrollment server from the mobile emulator. I came across a tool called EM IP Utility, installed it on the emulator and scaned it for assigned IP but the IP assigned to it is wrong. I have enabled the NE2000 PCMCIA network adapter and bind it to the VMWare Accelerated AMD PCNet Adapter.

Any reason why the emulator is not picking the IP address assigned to the server?

Assigned IP is 192.168.55.101
Expected IP is 192.168.10.xxx</description>
		<content:encoded><![CDATA[<p>Hi Andreas,</p>
<p>I have followed through all the steps but I seems to be having a problem connecting to the enrollment server from the mobile emulator. I came across a tool called EM IP Utility, installed it on the emulator and scaned it for assigned IP but the IP assigned to it is wrong. I have enabled the NE2000 PCMCIA network adapter and bind it to the VMWare Accelerated AMD PCNet Adapter.</p>
<p>Any reason why the emulator is not picking the IP address assigned to the server?</p>
<p>Assigned IP is 192.168.55.101<br />
Expected IP is 192.168.10.xxx</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-7356</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Thu, 26 Nov 2009 16:47:47 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-7356</guid>
		<description>Hold on, you&#039;re nearly there by now - it&#039;s no fun if you don&#039;t run into a couple of obstacles along the way :)

When it fails during enrollment with an error like this the steps you should check are:
- You have a valid SSL certificate for the enrollment site. (Should be fixed during install but you never know.)
- If you don&#039;t use mobileenroll.contoso.com as the address you will need to type it in manually on the device.
- The certificate will be checked so if you type in 192.168.x.y it will fail if the certificate isn&#039;t issued to this name.
- Are you using multiple domain names and e-mail addresses? Always test using the primary address if you&#039;re having problems.

Still no go? You could test the webservices on a desktop to see if you are eligible for enrollment.</description>
		<content:encoded><![CDATA[<p>Hold on, you&#8217;re nearly there by now &#8211; it&#8217;s no fun if you don&#8217;t run into a couple of obstacles along the way <img src='http://mobilitydojo.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>When it fails during enrollment with an error like this the steps you should check are:<br />
- You have a valid SSL certificate for the enrollment site. (Should be fixed during install but you never know.)<br />
- If you don&#8217;t use mobileenroll.contoso.com as the address you will need to type it in manually on the device.<br />
- The certificate will be checked so if you type in 192.168.x.y it will fail if the certificate isn&#8217;t issued to this name.<br />
- Are you using multiple domain names and e-mail addresses? Always test using the primary address if you&#8217;re having problems.</p>
<p>Still no go? You could test the webservices on a desktop to see if you are eligible for enrollment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael B. Abbott</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-7346</link>
		<dc:creator>Michael B. Abbott</dc:creator>
		<pubDate>Thu, 26 Nov 2009 06:34:16 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-7346</guid>
		<description>Well seems I missed a step in a technet article in while you linked to, heh.. I&#039;m up and going; however, I am unable to get my phone (Touch Pro 2) to enroll.  I&#039;ve entered the credentials as per the pre-enrollment wizard, but get:

&quot;We are unable to localte a server successfully, but enrollment could not complete.  Verify your e-mail address and enrollment password, and then try again.&quot;

I&#039;ve entered the information correctly..</description>
		<content:encoded><![CDATA[<p>Well seems I missed a step in a technet article in while you linked to, heh.. I&#8217;m up and going; however, I am unable to get my phone (Touch Pro 2) to enroll.  I&#8217;ve entered the credentials as per the pre-enrollment wizard, but get:</p>
<p>&#8220;We are unable to localte a server successfully, but enrollment could not complete.  Verify your e-mail address and enrollment password, and then try again.&#8221;</p>
<p>I&#8217;ve entered the information correctly..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael B. Abbott</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-7345</link>
		<dc:creator>Michael B. Abbott</dc:creator>
		<pubDate>Thu, 26 Nov 2009 05:17:55 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-7345</guid>
		<description>I&#039;ve run into a snag that despite putting a substantial effort into searching through on-line and performing some tasks suggested therein, I&#039;ve been unable to resolve.  Any pointers of where to look would be appreciated.

When I go to enroll a device I receive the following:

Summary: 1 item(s). 0 succeeded, 1 failed. 
Elapsed time: 00:00:00


Enrollment Data
Failed

Error:
You are not authorized to perform this action.

Mobile Device Manager Shell command attempted:
New-EnrollmentRequest -Owner &#039;CN=Domain Username Removed,CN=Users,DC=domainname,DC=ca&#039; -Name &#039;TouchPro2&#039; -Container &#039;OU=SCMDM Managed Devices (ALLSOL),DC=domainname,DC=ca&#039;

Elapsed Time: 00:00:00

---

BPA comes back with 4 warnings that are performance related (I&#039;m setting the servers up in VMWware (SCMDM = 2003 x64 Enterprise / Cert Server on Server 2003 x86) such as low ram, disk space, and processor speed. Everything else has green checkmarks.

I&#039;m running MDM Console as Aministrator and have ensured that account is part of the 5 crucial SCMDM groups and Domain Admins.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve run into a snag that despite putting a substantial effort into searching through on-line and performing some tasks suggested therein, I&#8217;ve been unable to resolve.  Any pointers of where to look would be appreciated.</p>
<p>When I go to enroll a device I receive the following:</p>
<p>Summary: 1 item(s). 0 succeeded, 1 failed.<br />
Elapsed time: 00:00:00</p>
<p>Enrollment Data<br />
Failed</p>
<p>Error:<br />
You are not authorized to perform this action.</p>
<p>Mobile Device Manager Shell command attempted:<br />
New-EnrollmentRequest -Owner &#8216;CN=Domain Username Removed,CN=Users,DC=domainname,DC=ca&#8217; -Name &#8216;TouchPro2&#8242; -Container &#8216;OU=SCMDM Managed Devices (ALLSOL),DC=domainname,DC=ca&#8217;</p>
<p>Elapsed Time: 00:00:00</p>
<p>&#8212;</p>
<p>BPA comes back with 4 warnings that are performance related (I&#8217;m setting the servers up in VMWware (SCMDM = 2003 x64 Enterprise / Cert Server on Server 2003 x86) such as low ram, disk space, and processor speed. Everything else has green checkmarks.</p>
<p>I&#8217;m running MDM Console as Aministrator and have ensured that account is part of the 5 crucial SCMDM groups and Domain Admins.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Larry</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-6117</link>
		<dc:creator>Larry</dc:creator>
		<pubDate>Thu, 08 Oct 2009 19:07:24 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-6117</guid>
		<description>Thanks for the reply. I&#039;ve been pulled into another project. I&#039;ll get back to MDM in a couple weeks, I hope.</description>
		<content:encoded><![CDATA[<p>Thanks for the reply. I&#8217;ve been pulled into another project. I&#8217;ll get back to MDM in a couple weeks, I hope.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-5989</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Thu, 01 Oct 2009 18:10:41 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-5989</guid>
		<description>The AD error regarding the portalurl not being created sounds like it&#039;s related to the self service portal although I have not seen that error before. (In MDM SP1 the portal is included by default, wheras in RTM it was an optional download.) While this might mean that the SSP is not working it should not affect the enrollment.

Provided you aren&#039;t trying to run them both on port 443 or a similar conflict. The SSP can be run on a different port, but the enrollment site needs to run on port 443 for devices to be able to enroll. Port 8445 is for the admin part of it, and it is correct that some of the web service methods can only be run from localhost. I have another post detailing how the web services work, and how they can be used.

Are you running multiple MDM roles on a single box (like in my test scenario) or have you split the roles over different boxes? Are you running the DC and MDM on the same server? This may create access issues. I cannot remember any issues using the domain admin account for administrating the MDM servers as long as this account is also a member of the MDM groups. (Remember to logout and login for the membership to apply.) I usually attempt device enrollment with a normal user account though.

If I were to troubleshoot the issue I&#039;d have a crack at the following steps:
- Check Event Viewer for any suspicious error messages.
- Check that you have the correct DNS entries. Records for mobileenroll, for the SSP, for MDM, etc. You can have multiple records pointing to the same IP address.
- Double check that certificates are installed, and are valid.
- Check IIS that the host names apply to the correct web site, the correct ports, and that there are no conflicts in the IIS setup.

If all is good you could attempt a repair install of the enrollment role.</description>
		<content:encoded><![CDATA[<p>The AD error regarding the portalurl not being created sounds like it&#8217;s related to the self service portal although I have not seen that error before. (In MDM SP1 the portal is included by default, wheras in RTM it was an optional download.) While this might mean that the SSP is not working it should not affect the enrollment.</p>
<p>Provided you aren&#8217;t trying to run them both on port 443 or a similar conflict. The SSP can be run on a different port, but the enrollment site needs to run on port 443 for devices to be able to enroll. Port 8445 is for the admin part of it, and it is correct that some of the web service methods can only be run from localhost. I have another post detailing how the web services work, and how they can be used.</p>
<p>Are you running multiple MDM roles on a single box (like in my test scenario) or have you split the roles over different boxes? Are you running the DC and MDM on the same server? This may create access issues. I cannot remember any issues using the domain admin account for administrating the MDM servers as long as this account is also a member of the MDM groups. (Remember to logout and login for the membership to apply.) I usually attempt device enrollment with a normal user account though.</p>
<p>If I were to troubleshoot the issue I&#8217;d have a crack at the following steps:<br />
- Check Event Viewer for any suspicious error messages.<br />
- Check that you have the correct DNS entries. Records for mobileenroll, for the SSP, for MDM, etc. You can have multiple records pointing to the same IP address.<br />
- Double check that certificates are installed, and are valid.<br />
- Check IIS that the host names apply to the correct web site, the correct ports, and that there are no conflicts in the IIS setup.</p>
<p>If all is good you could attempt a repair install of the enrollment role.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Larry</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-5949</link>
		<dc:creator>Larry</dc:creator>
		<pubDate>Tue, 29 Sep 2009 16:44:31 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-5949</guid>
		<description>Further troubleshooting, I attempted to access the enrollment directly through https://mobileenroll.domain.com:8445/MDM/enrollmentadminservice/admin.armx and I get a message indicating that I am not authorized. I am a domain administrator as well as a member of the scmdm server and security groups.

If I try to access the link from the hyper-v host (also a machine on the virtual network) I do get access to the Enrollment Admin web site with several links to enrollment administration . However, if I select any of the links it tells me that &quot;this test form is only available from the local machine&quot;.</description>
		<content:encoded><![CDATA[<p>Further troubleshooting, I attempted to access the enrollment directly through <a href="https://mobileenroll.domain.com:8445/MDM/enrollmentadminservice/admin.armx" rel="nofollow">https://mobileenroll.domain.com:8445/MDM/enrollmentadminservice/admin.armx</a> and I get a message indicating that I am not authorized. I am a domain administrator as well as a member of the scmdm server and security groups.</p>
<p>If I try to access the link from the hyper-v host (also a machine on the virtual network) I do get access to the Enrollment Admin web site with several links to enrollment administration . However, if I select any of the links it tells me that &#8220;this test form is only available from the local machine&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Larry</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-5934</link>
		<dc:creator>Larry</dc:creator>
		<pubDate>Mon, 28 Sep 2009 23:40:56 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-5934</guid>
		<description>Thank you Andreas... I setup and configured my lab exactly as your instructions except I installed MDM SP1.

The BPA Predeployment and Postdeployment test returned no errors. However, the Active Directory Validation had one error on the MDM Instance Property; Keyword portalurl was not created.

I have not found any reference to this error.

Then, when I do the device Pre-Enrollement and select a user from AD then click the CREATE button, it gives the following error;

Error Contacting Server https://mobileenroll.domain.com:8445/MDM/enrollmentadminservice/admin.armx
The request failed with HTTP status 401: Unauthorized

I am a domain admin and also in the SCMDS Server Admins group.

I don&#039;t know where to look for this or whether the AD Validation error is related to the failure to Pre-Enroll the device.

I would be most grateful for some direction.</description>
		<content:encoded><![CDATA[<p>Thank you Andreas&#8230; I setup and configured my lab exactly as your instructions except I installed MDM SP1.</p>
<p>The BPA Predeployment and Postdeployment test returned no errors. However, the Active Directory Validation had one error on the MDM Instance Property; Keyword portalurl was not created.</p>
<p>I have not found any reference to this error.</p>
<p>Then, when I do the device Pre-Enrollement and select a user from AD then click the CREATE button, it gives the following error;</p>
<p>Error Contacting Server <a href="https://mobileenroll.domain.com:8445/MDM/enrollmentadminservice/admin.armx" rel="nofollow">https://mobileenroll.domain.com:8445/MDM/enrollmentadminservice/admin.armx</a><br />
The request failed with HTTP status 401: Unauthorized</p>
<p>I am a domain admin and also in the SCMDS Server Admins group.</p>
<p>I don&#8217;t know where to look for this or whether the AD Validation error is related to the failure to Pre-Enroll the device.</p>
<p>I would be most grateful for some direction.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://mobilitydojo.net/2008/09/24/system-center-mobile-device-manager-2008-install-guide-no-gateway-part-3/comment-page-1/#comment-5790</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Tue, 22 Sep 2009 17:36:20 +0000</pubDate>
		<guid isPermaLink="false">http://mobilitydojo.net/?p=136#comment-5790</guid>
		<description>Some times one has to be clever creating workarounds :)

Glad to be of help if I pointed you in the right direction :)</description>
		<content:encoded><![CDATA[<p>Some times one has to be clever creating workarounds <img src='http://mobilitydojo.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Glad to be of help if I pointed you in the right direction <img src='http://mobilitydojo.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>
