Microsoft System Center Configuration Manager Administration Training Course

5 days Information Technology Certificate on completion
Course codeSD-IT-036
Duration5 days
LevelIntermediate
CategoryInformation Technology
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Managing Windows endpoints at enterprise scale requires more than deploying software packages. Administrators must maintain a reliable Configuration Manager hierarchy, discover devices accurately, target collections safely, deploy operating systems consistently, and prove patch and compliance status to security and leadership teams. When these tasks are handled through manual scripts, poorly controlled collections, or untested deployments, organisations face failed updates, inconsistent device builds, unnecessary service desk demand, and weak audit evidence.

This five-day Microsoft System Center Configuration Manager Administration Training Course teaches participants to administer Microsoft Configuration Manager current branch in an on-premises or hybrid enterprise environment. Participants configure site system roles, boundaries and boundary groups, discovery methods, client installation, collections, applications, packages, software updates, operating system deployment, compliance settings, and reporting. They also learn practical administration methods for pilot rings, maintenance windows, deployment monitoring, content distribution, client health troubleshooting, and role-based administration.

Training is delivered through instructor-led demonstrations, guided configuration labs, troubleshooting scenarios, and deployment-planning workshops using a realistic corporate endpoint estate. Each participant builds and documents a Configuration Manager administration runbook covering site configuration, collection strategy, application deployment, update servicing, OSD workflow, monitoring checks, and escalation actions. This tangible deliverable can be adapted for use in their own environment after the course.

The course is designed for IT professionals who already support Windows devices, Active Directory, endpoint services, or enterprise infrastructure and now need accountable operational control of Configuration Manager. It gives both practitioners and approving managers a structured route to safer endpoint management, more predictable change delivery, and measurable compliance reporting.

Course objectives

By the end of this course, participants will be able to:

  • Configure a Configuration Manager site hierarchy, site system roles, boundaries, and boundary groups for managed endpoint services
  • Implement Active Directory and network discovery methods to create an accurate managed-device inventory
  • Deploy and troubleshoot the Configuration Manager client using client push, installation properties, and log analysis
  • Build direct, query-based, and limiting collections to target users and devices with controlled deployment scope
  • Create applications, deployment types, detection methods, requirements, and dependencies for reliable software delivery
  • Manage software update groups, automatic deployment rules, servicing plans, and maintenance windows for patch governance
  • Deploy Windows operating systems using task sequences, boot images, driver packages, and deployment collections
  • Produce an operational Configuration Manager runbook covering monitoring, reporting, client health, and incident escalation

Benefits of attending

For you

  • Gain the ability to administer Configuration Manager deployments without relying solely on pre-existing task sequences or scripts
  • Build credible evidence of endpoint-management capability through a documented Configuration Manager administration runbook
  • Diagnose common client, content-distribution, discovery, and deployment issues using Configuration Manager logs and monitoring views
  • Improve readiness for Configuration Manager, endpoint engineering, desktop engineering, and IT operations administration roles
  • Develop a repeatable approach to designing pilot collections, phased deployments, maintenance windows, and rollback decisions

For your organisation

  • Reduce failed software and update deployments through better collection design, detection logic, and staged rollout controls
  • Improve endpoint patch visibility with managed software update groups, compliance monitoring, and reporting practices
  • Standardise Windows device provisioning through documented task sequences, boot images, driver packages, and deployment procedures
  • Lower operational risk by applying role-based administration, maintenance windows, approval points, and controlled targeting
  • Create reusable administration documentation that reduces dependence on individual staff knowledge and supports service continuity

Target competencies

Site infrastructure administrationCollection targeting designApplication deployment engineeringUpdate servicing managementOperating system deploymentClient health troubleshooting

Who should attend

  • Configuration Manager Administrators — who need to operate sites, clients, deployments, and endpoint servicing safely
  • Desktop Support Engineers — who support managed Windows devices and need to diagnose client and deployment failures
  • Endpoint Management Specialists — who administer enterprise application, update, compliance, and device-management services
  • Windows Server Administrators — who maintain Active Directory, WSUS, SQL Server, and infrastructure supporting Configuration Manager
  • IT Operations Engineers — who require controlled methods for software rollout, patching, monitoring, and service reporting
  • Technical Service Delivery Managers — who oversee endpoint-management teams and need to improve deployment governance and evidence

Requirements and prerequisites

Participants should have practical experience supporting Windows 10 or Windows 11 devices in an Active Directory domain and be comfortable with Windows Server administration concepts. Familiarity with DNS, DHCP, Group Policy, basic networking, PowerShell syntax, and software installation troubleshooting is expected. Participants should understand the purpose of SQL Server, WSUS, and endpoint patching, although they do not need to be database or WSUS specialists. Prior hands-on use of Microsoft Configuration Manager is helpful but not required. No programming, advanced SQL querying, Intune administration, or prior certification is required.

Training methodology

The course combines focused instructor-led explanation with guided administration labs in a Configuration Manager training environment. Participants configure site components, build collections, package applications, create update deployments, and run operating system task sequences rather than only reviewing console screens. Troubleshooting cases use realistic symptoms such as inactive clients, failed content distribution, unmet application requirements, and non-compliant updates. Small-group discussions examine rollout risk and governance decisions. The final workshop converts the lab configuration into a practical administration runbook and implementation plan for the participant’s own endpoint estate.

Course outline

Day 1: Configuration Manager architecture and client foundations

  • Microsoft Configuration Manager current branch architecture and administrative console navigation
  • Sites, site servers, primary sites, central administration sites, and hierarchy design principles
  • Management points, distribution points, software update points, and other site system roles
  • Active Directory schema extension and Configuration Manager publishing prerequisites
  • Boundaries, boundary groups, content location, and client site assignment
  • Active Directory discovery, network discovery, and device inventory population
  • Client installation methods, client settings, and core client log files

Workshop: Configure foundational site settings, boundaries, discovery methods, and a pilot client deployment, then document the resulting client-management design.

Day 2: Collections, inventory, applications, and content

  • Direct membership, query rules, include rules, exclude rules, and limiting collections
  • Collection evaluation, incremental updates, maintenance considerations, and targeting safety
  • Hardware inventory, software inventory, inventory classes, and asset intelligence concepts
  • Application model architecture, deployment types, detection methods, requirements, and dependencies
  • Package and program deployment compared with the application model
  • Content libraries, distribution points, distribution groups, and content validation
  • Deployment purposes, user experience settings, deadlines, notifications, and phased deployment controls

Workshop: Create pilot and production collections, package a business application with detection logic, and distribute it to a selected distribution point.

Day 3: Software updates, compliance, and endpoint configuration

  • WSUS integration, software update point configuration, products, classifications, and synchronisation
  • Software update groups, update deployment packages, and update content distribution
  • Automatic deployment rules for recurring monthly patch cycles
  • Maintenance windows, deployment deadlines, restart behaviour, and user notification controls
  • Windows servicing plans and feature update deployment strategy
  • Configuration baselines, configuration items, compliance rules, and remediation options
  • Software update compliance monitoring, built-in reports, and update deployment troubleshooting logs

Workshop: Build a monthly patch deployment workflow with an automatic deployment rule, pilot ring, maintenance window, and compliance report.

Day 4: Operating system deployment and endpoint lifecycle

  • Operating system deployment architecture and task sequence planning
  • Windows Assessment and Deployment Kit components, boot images, and Windows PE customisation
  • Operating system images, install packages, image servicing, and image deployment choices
  • Task sequence variables, task sequence steps, conditions, and error handling
  • Driver packages, driver selection profiles, and hardware model targeting
  • PXE-enabled distribution points, multicast considerations, and unknown computer support
  • User State Migration Tool concepts, in-place upgrades, and deployment monitoring

Workshop: Create and test a Windows deployment task sequence that applies an operating system image, drivers, applications, and post-build configuration.

Day 5: Operations, security, troubleshooting, and service improvement

  • Role-based administration, security roles, security scopes, and administrative users
  • Status messages, alerts, monitoring workspaces, and operational dashboard interpretation
  • Client health assessment using client activity, policy evaluation, and component status
  • Configuration Manager log locations, CMTrace usage, and log-driven troubleshooting methods
  • Content distribution, boundary, application detection, and software update failure diagnosis
  • SQL Server reporting services integration, built-in reports, and report subscription options
  • Backup, recovery, change control, documentation, and Configuration Manager administration governance

Workshop: Resolve a multi-symptom endpoint deployment incident and complete a Configuration Manager administration runbook with monitoring, escalation, and improvement actions.

Tools & standards covered

Microsoft Configuration Manager current branch, Windows Assessment and Deployment Kit, Windows Server Update Services, SQL Server Management Studio

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should be comfortable supporting Windows devices in an Active Directory environment and understand basic DNS, DHCP, Group Policy, and networking concepts. You do not need previous Configuration Manager administration experience, but the course moves beyond introductory Windows support.

No personal Configuration Manager installation is required for the practical work. A configured lab environment is used for console-based administration exercises, including client deployment, application delivery, updates, and task sequences.

It is suitable for Intune administrators who also support Microsoft Configuration Manager or a co-managed Windows estate. The course focuses on Configuration Manager current branch administration rather than Intune policy design, mobile device management, or cloud-only endpoint management.

This course concentrates on the operational administration of on-premises Configuration Manager infrastructure, clients, collections, content, software updates, and operating system deployment. General endpoint management courses often place greater emphasis on Intune, Entra ID, and cloud management scenarios.

The labs mirror routine administration work such as creating safe pilot collections, deploying applications with detection rules, managing monthly updates, and troubleshooting inactive clients. Participants also produce a runbook structure that can be adapted to their organisation's hierarchy, change controls, and support model.

You leave with practical configuration experience across the main Configuration Manager workloads and a documented administration runbook created during the course. The runbook covers site roles, collection strategy, deployment checks, patching, operating system deployment, reporting, and escalation actions.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Information Technology

10 Days Certificate

Jira Service Management Configuration Training Course

Jira Service Management (JSM) can become difficult to govern when service projects, request types, workflows, queues, SLAs and automations h…

10 Days Certificate

Oil and Gas Information Technology Operations Training Course

Oil and gas operations depend on reliable, secure information flows across upstream assets, pipelines, terminals, refineries, trading functi…

5 Days Certificate

Microsoft PowerShell Automation for IT Administrators Training Course

IT administrators are frequently asked to complete repeatable work at scale: provision accounts, inspect server health, collect audit eviden…

5 Days Certificate

COBIT 2019 IT Governance Implementation Training Course

Organisations often have IT controls, risk registers, architecture standards and performance dashboards, yet still struggle to show how tech…