The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Console Connections is the Configuration Manager view for seeing recent connections made through the ConfigMgr console. Open Administration > Security > Console Connections to view the user, computer, connected site, console version, and the latest console heartbeat. It is an operational session view—not a complete audit of PowerShell, SDK, or administrator actions.
What Console Connections shows
Microsoft documents the view as showing active and recently connected Configuration Manager consoles. Records older than 30 days are removed, so it is not suitable for long-term history or compliance evidence. See Microsoft’s Console Connections documentation.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
System Center 2012 R2 Configuration Manager: A Practical Handbook for Reporting | $55.00 | Buy on Amazon |
- User name and machine name
- Connected site code
- Console version
- Last Console Heartbeat (older releases may call this Last Connected Time)
- Source and Startup Time where exposed by that release
A foreground console sends a heartbeat approximately every 10 minutes. A recent heartbeat is a better activity indicator than the mere presence of a row, but it does not prove that the administrator is currently changing objects. A console can be backgrounded, disconnected, or recently closed while its record remains visible.
Open the node
- Open the Configuration Manager console.
- Select Administration.
- Expand Security.
- Select Console Connections.
Labels can vary slightly with console language and release. A console connects to a central administration site or primary site, not directly to a secondary site. In a multi-provider site, the displayed result depends on the SMS Provider reached by the console.
Free tools Windows power users keep installed
One-click scans. No signup required.
What it does—and does not—track
The feature covers connections made by the Configuration Manager console. It does not list PowerShell sessions, other SDK-based SMS Provider clients, every WMI or Administration Service consumer, or a complete record of administrative actions. For object-change auditing, use Configuration Manager auditing and status messages together with identity, endpoint-security, reporting, or SIEM data. Console Connections is appropriate for quickly finding who may be using the console, the source computer, and the connected site.
Prerequisites
| Requirement | What it means |
|---|---|
SMS_Site Read permission |
The viewing account needs Read permission on the site object. Local administrator status on the workstation is not a substitute. |
| Administration Service | The console uses the SMS Provider’s Administration Service REST API to retrieve this information. |
| HTTPS path | DNS, certificate trust, TCP 443, and any proxy or TLS-inspection device must permit the request. |
| IIS | Required for the Administration Service in Configuration Manager 2006 and earlier; not a universal requirement from version 2010 onward. |
| Console .NET requirement | Configuration Manager 2403 requires .NET Framework 4.8 when the console is installed on other devices. This is separate from historical Administration Service prerequisites. |
| CMG access | Only environments intentionally using Administration Service through a Cloud Management Gateway need the additional CMG configuration. |
Why the Administration Service matters
The console communicates with an SMS Provider, which exposes the Administration Service over HTTPS. Console Connections uses that REST service; therefore, other console areas can work while this node is empty or reports a service connection error. Microsoft’s architecture and setup references are Administration Service overview and Administration Service setup.
Fix an empty or missing Console Connections node
1. Confirm visibility and role permissions
If the node is absent, check the console and site-version compatibility, the assigned security role, security scopes, and role-based visibility. If it is visible but empty, verify that the account has Read permission on SMS_Site. Test with a known-good account only as a controlled diagnostic, not as a permanent workaround.
2. Test the Administration Service endpoint
From the console computer or an appropriate administrative workstation, request:
https://<SMSProviderFQDN>/AdminService/v1.0/$metadata
For example:
https://smsprovider.contoso.com/AdminService/v1.0/$metadata
A working endpoint returns service metadata. Connection, certificate, authorization, DNS, or HTTP errors identify a path that still needs correction. This test does not by itself prove that the user’s role or the Console Connections feature is fully functional.
3. Validate DNS, HTTPS, certificates, and port 443
- Resolve the SMS Provider FQDN used by the console.
- Confirm TCP 443 reachability.
- Check certificate validity, trust chain, and subject/SAN matching the name in the URL.
- Check certificate binding on the SMS Provider and look for expiry or TLS errors.
- Check proxy and TLS-inspection devices for altered or blocked requests.
Enhanced HTTP can use Configuration Manager’s certificate mechanisms in supported scenarios; a manually deployed PKI certificate is not automatically required in every deployment. Follow the Microsoft setup guidance for the site’s security mode.
4. Check provider health and proxy behavior
In a site with multiple SMS Providers, test the provider the console is actually using and then test each relevant provider. One unavailable provider can cause failures even when the site server appears healthy. Also compare WinHTTP, Internet Options, authentication-required proxy, and TLS-inspection behavior from the console workstation; Microsoft notes that proxy use can prevent Administration Service connections.
5. Review the relevant logs
| Log | Where and what to inspect |
|---|---|
AdminService.log |
Administration Service request and response activity on the SMS Provider. |
SMS_REST_PROVIDER.log |
REST provider startup and service-health information. |
RESTPROVIDERSetup.log |
Installation and setup problems. |
SmsAdminUI.log |
Console-side errors; the AdminConsole log directory varies by installation. |
Microsoft’s normal server log directory is C:Program FilesMicrosoft Configuration Managerlogs. Capture timestamps while reproducing the problem so console and provider entries can be correlated.
6. Check component status, then retest
Review Monitoring > System Status > Component Status and, where exposed by the release, the SMS_REST_PROVIDER component. A running component does not rule out certificate, DNS, proxy, authorization, or firewall faults.
- Correct the identified permission, network, certificate, or provider issue.
- Close and reopen the console.
- Open Administration > Security > Console Connections.
- Keep the console in the foreground and wait for the roughly 10-minute heartbeat interval when testing activity.
- Review logs during the test and, if possible, compare with a second console computer.
Records are not necessarily reconstructed retroactively for a period when the Administration Service was unavailable.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Version notes that prevent common mistakes
| Release | Relevant change |
|---|---|
| 1902 | Historical documentation and contemporary coverage identify the introduction of recent console-connection visibility. |
| 1910 | Heartbeat-oriented terminology and periodic foreground heartbeats replaced older Last Connected Time wording in Microsoft documentation. |
| 2010 | IIS is no longer required on the SMS Provider for the Administration Service. |
| 2111 | The separate option to enable console use of the Administration Service was removed; the service is on and used when needed. |
| 2403 | .NET Framework 4.8 is required for consoles installed on other devices. |
Use the release-specific Microsoft documentation rather than applying an old blog checklist unchanged.
Advanced SQL investigation
An HTMD troubleshooting article lists objects such as AdminConsoleUsage, Console_Files, ConsoleUsageData, SYSTEM_CONSOLE_USAGE_DATA, SYSTEM_CONSOLE_USAGE_HIST, SYSTEM_CONSOLE_USER_DATA, and SYSTEM_CONSOLE_USER_HIST. Its examples include:
SELECT * FROM AdminConsoleUsage;
SELECT * FROM Console_Files;
SELECT * FROM ConsoleUsageData;
SELECT * FROM SYSTEM_CONSOLE_USAGE_DATA;
SELECT * FROM SYSTEM_CONSOLE_USAGE_HIST;
SELECT * FROM SYSTEM_CONSOLE_USER_DATA;
SELECT * FROM SYSTEM_CONSOLE_USER_HIST;
These are practical diagnostic examples from HTMD, not a guaranteed, version-stable reporting contract on Microsoft’s end-user page. Internal schemas can change, expose sensitive user and workstation data, and impose database load. Validate object names on the target release, use a read-only account, avoid direct writes, and prefer supported console, Administration Service, logging, and controlled reporting methods. Avoid deploying SELECT * as production reporting.
Teams chat from the node
Where supported, the node can start a Microsoft Teams chat with another administrator. The target must be discovered through Microsoft Entra ID or AD User Discovery and have a resolvable User Principal Name, and Teams must be installed on the console computer. A missing UPN can gray out the action; Microsoft also documents an error path when Teams is not installed, including a known Windows uninstall-registry-key issue.
Choose the right tool
| Requirement | Appropriate source |
|---|---|
| See recent ConfigMgr console users, machines, and versions | Console Connections |
| Track PowerShell or SDK connections | Separate service, identity, endpoint, or SIEM monitoring |
| Determine which objects changed | Configuration Manager auditing and status messages |
| Retain usage beyond 30 days | Controlled reporting or SIEM/data-retention solution |
| Investigate sign-ins | Microsoft Entra ID and Windows security logs |
The Bottom Line
For an empty or unavailable Console Connections view, check SMS_Site Read permission, test the Administration Service metadata URL, verify HTTPS/certificate/TCP 443 and proxy paths, confirm SMS Provider health, and correlate AdminService.log, SMS_REST_PROVIDER.log, RESTPROVIDERSetup.log, and SmsAdminUI.log. Do not install IIS solely because an old guide says it is required: that requirement applies to Configuration Manager 2006 and earlier.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




