Documentation for SCCM task sequence deployment orchestrator

AD - Parent AD group for AD group list

A realms parent active directory group is the parent group for all the active directory groups that should be displayed for the sccmtspsi Realm instance.

The name of the active directory group should be similar to the below entry.

sccmtspsi-groups-XXX [Where XXX is the Realm name]

The Realm broker account should have permissions to add members into the above group.

The Realm broker account should have permissions to add members into the groups that are members of the “sccmtspsi-groups-r01” [where r01 is the Realm name] group.

View of the above active directory groups in sccmtspsi. The below is a GIF (Graphics in file) image (Turn on animation in Internet Explorer).

Image showing AD groups listed within the sccmtspsi application console.

Suggest Edit

DCOM hardening issue.

This application fails to authenticate with WMI on the SCCM server because Microsoft has not yet hardened DCOM on their Windows Preinstallation Environment. We are working on a different approach, but it will only be released during the first quarter of 2024. But until that time, the only workaround will be to uninstall the update corresponding to KB5004442.