Microsoft System Center Configuration Manager Administration Training Course
| Course code | SD-IT-036 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Information Technology |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Managing Windows endpoints at enterprise scale requires more than deploying software packages. Administrators must maintain a reliable Configuration Manager hierarchy, discover devices accurately, target collections safely, deploy operating systems consistently, and prove patch and compliance status to security and leadership teams. When these tasks are handled through manual scripts, poorly controlled collections, or untested deployments, organisations face failed updates, inconsistent device builds, unnecessary service desk demand, and weak audit evidence.
This five-day Microsoft System Center Configuration Manager Administration Training Course teaches participants to administer Microsoft Configuration Manager current branch in an on-premises or hybrid enterprise environment. Participants configure site system roles, boundaries and boundary groups, discovery methods, client installation, collections, applications, packages, software updates, operating system deployment, compliance settings, and reporting. They also learn practical administration methods for pilot rings, maintenance windows, deployment monitoring, content distribution, client health troubleshooting, and role-based administration.
Training is delivered through instructor-led demonstrations, guided configuration labs, troubleshooting scenarios, and deployment-planning workshops using a realistic corporate endpoint estate. Each participant builds and documents a Configuration Manager administration runbook covering site configuration, collection strategy, application deployment, update servicing, OSD workflow, monitoring checks, and escalation actions. This tangible deliverable can be adapted for use in their own environment after the course.
The course is designed for IT professionals who already support Windows devices, Active Directory, endpoint services, or enterprise infrastructure and now need accountable operational control of Configuration Manager. It gives both practitioners and approving managers a structured route to safer endpoint management, more predictable change delivery, and measurable compliance reporting.
Course objectives
By the end of this course, participants will be able to:
- Configure a Configuration Manager site hierarchy, site system roles, boundaries, and boundary groups for managed endpoint services
- Implement Active Directory and network discovery methods to create an accurate managed-device inventory
- Deploy and troubleshoot the Configuration Manager client using client push, installation properties, and log analysis
- Build direct, query-based, and limiting collections to target users and devices with controlled deployment scope
- Create applications, deployment types, detection methods, requirements, and dependencies for reliable software delivery
- Manage software update groups, automatic deployment rules, servicing plans, and maintenance windows for patch governance
- Deploy Windows operating systems using task sequences, boot images, driver packages, and deployment collections
- Produce an operational Configuration Manager runbook covering monitoring, reporting, client health, and incident escalation
Benefits of attending
For you
- Gain the ability to administer Configuration Manager deployments without relying solely on pre-existing task sequences or scripts
- Build credible evidence of endpoint-management capability through a documented Configuration Manager administration runbook
- Diagnose common client, content-distribution, discovery, and deployment issues using Configuration Manager logs and monitoring views
- Improve readiness for Configuration Manager, endpoint engineering, desktop engineering, and IT operations administration roles
- Develop a repeatable approach to designing pilot collections, phased deployments, maintenance windows, and rollback decisions
For your organisation
- Reduce failed software and update deployments through better collection design, detection logic, and staged rollout controls
- Improve endpoint patch visibility with managed software update groups, compliance monitoring, and reporting practices
- Standardise Windows device provisioning through documented task sequences, boot images, driver packages, and deployment procedures
- Lower operational risk by applying role-based administration, maintenance windows, approval points, and controlled targeting
- Create reusable administration documentation that reduces dependence on individual staff knowledge and supports service continuity
Target competencies
Who should attend
- Configuration Manager Administrators — who need to operate sites, clients, deployments, and endpoint servicing safely
- Desktop Support Engineers — who support managed Windows devices and need to diagnose client and deployment failures
- Endpoint Management Specialists — who administer enterprise application, update, compliance, and device-management services
- Windows Server Administrators — who maintain Active Directory, WSUS, SQL Server, and infrastructure supporting Configuration Manager
- IT Operations Engineers — who require controlled methods for software rollout, patching, monitoring, and service reporting
- Technical Service Delivery Managers — who oversee endpoint-management teams and need to improve deployment governance and evidence
Requirements and prerequisites
Participants should have practical experience supporting Windows 10 or Windows 11 devices in an Active Directory domain and be comfortable with Windows Server administration concepts. Familiarity with DNS, DHCP, Group Policy, basic networking, PowerShell syntax, and software installation troubleshooting is expected. Participants should understand the purpose of SQL Server, WSUS, and endpoint patching, although they do not need to be database or WSUS specialists. Prior hands-on use of Microsoft Configuration Manager is helpful but not required. No programming, advanced SQL querying, Intune administration, or prior certification is required.
Training methodology
The course combines focused instructor-led explanation with guided administration labs in a Configuration Manager training environment. Participants configure site components, build collections, package applications, create update deployments, and run operating system task sequences rather than only reviewing console screens. Troubleshooting cases use realistic symptoms such as inactive clients, failed content distribution, unmet application requirements, and non-compliant updates. Small-group discussions examine rollout risk and governance decisions. The final workshop converts the lab configuration into a practical administration runbook and implementation plan for the participant’s own endpoint estate.
Course outline
Day 1: Configuration Manager architecture and client foundations
- Microsoft Configuration Manager current branch architecture and administrative console navigation
- Sites, site servers, primary sites, central administration sites, and hierarchy design principles
- Management points, distribution points, software update points, and other site system roles
- Active Directory schema extension and Configuration Manager publishing prerequisites
- Boundaries, boundary groups, content location, and client site assignment
- Active Directory discovery, network discovery, and device inventory population
- Client installation methods, client settings, and core client log files
Workshop: Configure foundational site settings, boundaries, discovery methods, and a pilot client deployment, then document the resulting client-management design.
Day 2: Collections, inventory, applications, and content
- Direct membership, query rules, include rules, exclude rules, and limiting collections
- Collection evaluation, incremental updates, maintenance considerations, and targeting safety
- Hardware inventory, software inventory, inventory classes, and asset intelligence concepts
- Application model architecture, deployment types, detection methods, requirements, and dependencies
- Package and program deployment compared with the application model
- Content libraries, distribution points, distribution groups, and content validation
- Deployment purposes, user experience settings, deadlines, notifications, and phased deployment controls
Workshop: Create pilot and production collections, package a business application with detection logic, and distribute it to a selected distribution point.
Day 3: Software updates, compliance, and endpoint configuration
- WSUS integration, software update point configuration, products, classifications, and synchronisation
- Software update groups, update deployment packages, and update content distribution
- Automatic deployment rules for recurring monthly patch cycles
- Maintenance windows, deployment deadlines, restart behaviour, and user notification controls
- Windows servicing plans and feature update deployment strategy
- Configuration baselines, configuration items, compliance rules, and remediation options
- Software update compliance monitoring, built-in reports, and update deployment troubleshooting logs
Workshop: Build a monthly patch deployment workflow with an automatic deployment rule, pilot ring, maintenance window, and compliance report.
Day 4: Operating system deployment and endpoint lifecycle
- Operating system deployment architecture and task sequence planning
- Windows Assessment and Deployment Kit components, boot images, and Windows PE customisation
- Operating system images, install packages, image servicing, and image deployment choices
- Task sequence variables, task sequence steps, conditions, and error handling
- Driver packages, driver selection profiles, and hardware model targeting
- PXE-enabled distribution points, multicast considerations, and unknown computer support
- User State Migration Tool concepts, in-place upgrades, and deployment monitoring
Workshop: Create and test a Windows deployment task sequence that applies an operating system image, drivers, applications, and post-build configuration.
Day 5: Operations, security, troubleshooting, and service improvement
- Role-based administration, security roles, security scopes, and administrative users
- Status messages, alerts, monitoring workspaces, and operational dashboard interpretation
- Client health assessment using client activity, policy evaluation, and component status
- Configuration Manager log locations, CMTrace usage, and log-driven troubleshooting methods
- Content distribution, boundary, application detection, and software update failure diagnosis
- SQL Server reporting services integration, built-in reports, and report subscription options
- Backup, recovery, change control, documentation, and Configuration Manager administration governance
Workshop: Resolve a multi-symptom endpoint deployment incident and complete a Configuration Manager administration runbook with monitoring, escalation, and improvement actions.
Tools & standards covered
Microsoft Configuration Manager current branch, Windows Assessment and Deployment Kit, Windows Server Update Services, SQL Server Management Studio
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Information Technology
Jira Service Management Configuration Training Course
Jira Service Management (JSM) can become difficult to govern when service projects, request types, workflows, queues, SLAs and automations h…
Oil and Gas Information Technology Operations Training Course
Oil and gas operations depend on reliable, secure information flows across upstream assets, pipelines, terminals, refineries, trading functi…
Microsoft PowerShell Automation for IT Administrators Training Course
IT administrators are frequently asked to complete repeatable work at scale: provision accounts, inspect server health, collect audit eviden…
COBIT 2019 IT Governance Implementation Training Course
Organisations often have IT controls, risk registers, architecture standards and performance dashboards, yet still struggle to show how tech…