1. Overview
  2. Realm setup
  3. Active Directory & SCCM setup.
    1. Active directory - Security group
    2. Active directory - Broker account
    3. SCCM - Deployment collection
    4. SCCM - Administrative category for applications
    5. SCCM - Administrative category for office
    6. SCCM - Limiting collection for collections
    7. AD - Parent AD group for AD group list
    8. AD - Staging OU
    9. SCCM - Configuration directory
    10. SCCM - WinPE boot image setup
  4. Configuration tool & File
    1. Realm secret key
    2. Allowed WinPE instances
    3. Network access account
    4. Notification account
    5. Hostname formatting
    6. Automatically identify hostname
    7. Overrides
    8. Active directory staging OU
    9. MBAM Server details
    10. SMTP server details
    11. Notification types
    12. User state migration (USMT)
      1. Data store encryption
      2. Migration types
      3. Free space
      4. Config XML
      5. Migration rules XML
      6. Ignore return error codes
      7. Migrating EFS files
      8. Move domain
      9. Move user
      10. Currupt user profiles
    13. Logs and Profiles location
    14. Disk setup
    15. Content availability check
    16. Error adding collection member
    17. Error adding AD group member
    18. Wait for Bitlocker decryption
    19. Approved hardware
    20. Extension Attributes
  5. Using sccmtspsi (Operator view)
    1. sccmtspsi login window content
    2. sccmtspsi controls
      1. Asset hostname
      2. Unlock bitlocker
      3. Get task sequence deployments
      4. Get operating system images and packages
      5. Get office application
      6. Get SCCM applications
      7. Get SCCM collections
      8. Get AD Groups
      9. sccmtspsi actions
      10. Data migration options
      11. Primary users
      12. AD / SCCM entry
      13. Extension Attributes
  6. Task sequence steps
    1. sccmtspsi-tasksequence.exe
    2. Task sequence variables
    3. Apply operating system image step
  7. Requesting a offline Token (Optional)
  8. Task sequence error codes
  9. sccmtspsi error codes

3.9.SCCM - Configuration directory #

Create a folder with the name sccmtspsi on one of the drives on the SCCM management point.

Share the above folder and give it a share name sccmtspsi.

Grant ‘ReadShare and NTFS permission to the below security group [Implement strict access controls by removing other security principals].

sccmtspsi-users-XXX [Where XXX is the Realm name]

Create a sub-folder and give it the same name as your Realm.¬† If you’ve got multiple realm’s your setup will look similar to the below image.

In the below image r01, ret and xyz are realm names.

Create the following sub-folders inside the newly created sub-folder (named after the Realm)

  1. token
  2. usmt
  3. patch

Break inheritance and only grant read access to the realm broker account “sccmtspsi-broker-r01” [r01 is the name of the Realm] for the three sub-folders. Only the Realm broker and administrators will have access to these folders.

The configuration file :

This is an integral part of SCCMTSPSI. The file “sccmtspsi.config” holds within it the configuration data necessary for SCCMTSPSI to function.

The configuration file is created using the SCCMTSPSI configuration tool. Information on how to create the configuration file using the tool has been documented in another section.

The configuration file resides in configuration directory for the Realm as seen in the image below.


Token folder:

Both free and paid license tokens will be placed inside the ‘token’ sub-folder.

Full license:


Free license:

USMT folder:

Save USMT XML files into the “usmt” folder under the Realm configuration directory. In the below image “r01” is the Realm name.

Patch folder:

Special custom subroutines can be initiated at various parts during sccmtspsi run-time.

On request we can develop patches to accomplish tasks  specific to your environment.

These patches should be copied to the ‘patch’ sub-folder.

