What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Microsoft Configuration Manager is Microsoft’s enterprise endpoint-management platform for deploying applications, operating systems, software updates, policies, inventory, compliance settings, and administrative actions across Windows environments. It is the current name for the product formerly known as System Center Configuration Manager, Microsoft Endpoint Configuration Manager, or SCCM.
Configuration Manager remains supported and useful in 2026, especially for large Windows estates with complex application packaging, traditional imaging, branch-office distribution, and established on-premises operations. Microsoft’s strategic direction is not simply to replace it with Intune: organizations can retain Configuration Manager, connect it to Microsoft cloud services, adopt co-management, or migrate selected workloads to Intune.
What happened to SCCM?
The product’s naming history is:
- Systems Management Server (SMS)
- System Center Configuration Manager
- Microsoft Endpoint Configuration Manager
- Microsoft Configuration Manager
SCCM and ConfigMgr remain common industry names. The rebranding did not remove the on-premises product. Microsoft describes Configuration Manager as the on-premises component of the broader Microsoft Intune family. Intune and Configuration Manager are related, but they are not interchangeable names: Intune is a cloud service, while Configuration Manager relies on site infrastructure, a database, site roles, and an installed client.
What Configuration Manager does
Configuration Manager is much more than a software-deployment tool. It provides centralized control over enterprise Windows devices and servers.
#1 Best Overall
Applications
Administrators can deploy MSI and executable applications using detection methods, requirement rules, dependencies, supersedence, phased deployments, approval workflows, and user- or device-based targeting. Users typically interact with available software through Software Center, while required applications install according to deployment settings, deadlines, maintenance windows, and restart rules.
Software updates
Configuration Manager can synchronize Microsoft updates, organize them into software-update groups, create deployment packages, apply automatic deployment rules, and monitor compliance. Maintenance windows provide control over when updates and restarts occur.
In co-managed environments, update authority must be deliberately assigned between Configuration Manager and Windows Update for Business through Intune. Microsoft’s 2603 hotfix documentation describes a fix for cases where Windows Update scan-source settings could be incorrectly redirected when third-party updates were enabled.
Operating-system deployment
Task sequences support bare-metal deployment, PXE boot, boot images, operating-system images, driver packages, in-place upgrades, application installation, pre-provisioning, and user-state migration. This remains a major Configuration Manager strength.
However, not every modern Windows provisioning scenario requires imaging. Cloud-first organizations may use Windows Autopilot and Intune instead, while retaining Configuration Manager task sequences for specialized or legacy deployment requirements.
Inventory, reporting, and collections
Hardware inventory, software inventory, discovery data, collections, compliance reports, and deployment status provide detailed operational visibility. Reporting commonly depends on SQL Server Reporting Services components and the Configuration Manager reporting infrastructure.
CMPivot provides near-real-time queries across clients, while PowerShell scripting enables administrative actions and automation. These capabilities are particularly valuable when administrators need immediate information about configuration, processes, registry values, or installed software.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteCompliance and security
Configuration baselines can check desired-state settings and, where appropriate, remediate deviations. Other capabilities include endpoint protection integration, BitLocker management, compliance settings, and integration with Microsoft Defender and other Microsoft services. In co-managed estates, some security and compliance workloads may instead be controlled by Intune.
Rank #2
How the architecture works
A Configuration Manager deployment consists of several cooperating parts:
- Site servers: host the central management infrastructure.
- SQL Server database: stores configuration, inventory, deployment, and operational data.
- Management points: provide policy and communication services to clients.
- Distribution points: store and deliver application, update, operating-system, and driver content.
- Software-update point: synchronizes and manages update metadata.
- Configuration Manager client: the agent installed on managed devices.
- Administration console: the administrator interface.
- Software Center: the end-user software catalog.
- Cloud management gateway (CMG): extends Configuration Manager management to internet-based clients.
Large environments may use a central administration site (CAS), primary sites, and secondary sites. A standalone primary site is sufficient for many organizations. Other optional roles include state migration points, reporting services points, and the service connection point.
Boundaries and boundary groups
Boundaries and boundary groups determine which management point and distribution point a client uses, where content is downloaded, and how devices behave when they move between offices or networks.
This design is operationally critical. Poor boundary configuration can send clients to the wrong distribution point, increase WAN traffic, delay policy retrieval, or cause inconsistent software-update behavior. Boundary planning should account for sites, subnets, VPNs, cloud networks, roaming laptops, and remote offices rather than being treated as a one-time installation detail.
SQL Server requirements
Each site requires a supported SQL Server database. Microsoft supports a full SQL Server installation for central administration and primary sites. Secondary sites can use a full SQL Server instance or SQL Server Express within the documented limits. See Microsoft’s supported SQL Server versions.
Configuration Manager version 2603 adds support for SQL Server 2025 RTM for CAS, primary, and secondary site databases, and SQL Server 2025 Express for secondary sites. Microsoft recommends database compatibility level 160 for SQL Server 2025 with version 2603.
Configuration Manager, Intune, tenant attach, and co-management
Configuration Manager alone
In this model, devices are primarily managed by the Configuration Manager client and on-premises site infrastructure. It is a strong fit when an organization needs complex application deployment, traditional imaging, detailed content distribution, maintenance windows, or limited cloud dependence.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Intune alone
Microsoft Intune is a cloud-based endpoint-management service. It is generally better suited to internet-based devices, mobile-device management, cloud-first provisioning, Microsoft Entra integration, and organizations that do not want to operate site servers and SQL infrastructure.
Intune is not automatically a universal replacement. Configuration Manager may remain stronger for complex legacy applications, task sequences, local content distribution, and highly customized Windows operations.
Tenant attach
Tenant attach uploads Configuration Manager device information to the Intune admin center and enables selected cloud-console actions without transferring every management workload to Intune. It is primarily a visibility and administrative integration mechanism.
Microsoft documents limitations, including the fact that Configuration Manager devices are not included when retrieving a device list through a PowerShell script or Microsoft Graph API. The documented workaround is to export the list from the All devices page in the admin center. See the tenant-attach prerequisites.
Co-management
Co-management lets a Windows device be managed by both Configuration Manager and Intune. Administrators assign authority workload by workload and can pilot changes with device collections. Common workload areas include compliance, Windows Update, resource access, endpoint protection, client applications, Office Click-to-Run apps, and device configuration.
Co-management is not a mode in which both products automatically control everything. Each workload needs an owner. Poorly planned transitions can produce conflicting policies, unclear responsibility, or unexpected update behavior. Microsoft’s co-management documentation lists the relevant prerequisites and workload controls.
Cloud attach and CMG
Cloud attach is the broader connection between Configuration Manager and Microsoft cloud capabilities. It can include tenant attach, co-management, Endpoint analytics, and related integrations. A Cloud Management Gateway allows internet-based clients to communicate with Configuration Manager without requiring a traditional VPN, but it does not remove the need for Configuration Manager site infrastructure.
Is Configuration Manager still relevant in 2026?
Yes, particularly for large or complex Windows environments. Its strongest use cases include:
Recommended Free Tools
- Large Windows fleets with established Configuration Manager operations
- Complex application packaging and deployment requirements
- Traditional imaging and task-sequence workflows
- Branch offices needing controlled local content distribution
- Detailed collections, maintenance windows, inventory, and reporting
- Organizations requiring gradual cloud modernization rather than an immediate migration
It is a weaker fit for a small, cloud-first organization that has no appetite for SQL Server, site-server maintenance, packaging infrastructure, or endpoint-engineering operations. Such organizations may be better served by Intune-first management.
Rank #4
The real strategic choice is usually one of four models: Configuration Manager alone, Configuration Manager with cloud attach, co-management, or Intune-first management.
Current servicing model and version 2603
Configuration Manager uses a current branch servicing model. Updates are delivered through the in-console update mechanism, and each current-branch version is supported for 18 months from general availability. Organizations can generally skip an update and install a newer cumulative version when the supported upgrade path allows it. New site installations use baseline media; existing sites normally update in-console.
As of August 18, 2026, Microsoft’s latest major current-branch release identified in the documentation is version 2603, globally available on May 27, 2026. It can be installed in-console on sites running version 2409 or later. This time-sensitive status should be rechecked before an upgrade.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Notable 2603 changes include:
- SQL Server 2025 support
- Removal of the SQL Server Native Client dependency
- Stronger Network Access Account protections
- Disabled weak DHE cipher suites on CMG instances
- Improved ARM64 support
- New internet-access requirements for certain Microsoft Entra token-validation scenarios
Version 2603 upgrade warnings
Before upgrading, review these issues:
- Compliance checks: Microsoft says an internal compliance-check service will be deprecated in October 2026. In certain co-managed environments where Intune owns the Compliance workload, Software Center compliance checks may fail without the relevant update.
- Management-point internet access: Certain Microsoft Entra token scenarios require access to
https://login.microsoftonline.comandhttps://sts.windows.net. Environments using only on-premises Active Directory authentication are not affected by this specific requirement. - CMG cryptography: Test legacy clients, proxies, TLS inspection, and security appliances because weak DHE cipher suites are disabled.
- SQL Native Client: Configuration Manager no longer depends on it, but unrelated scripts or applications may still rely on
sqlncli.msi. - ARM64: Validate ARM64 driver imports, Windows 11 upgrade paths, and client installation.
Microsoft also documents a security update affecting imported Configuration Manager console extensions. Review the console-extension security information and apply supported fixes.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Prerequisites and licensing
Infrastructure
- Supported Windows Server roles and features
- Supported SQL Server configuration
- DNS, name resolution, storage, and network planning
- Firewall and proxy rules
- Service accounts and appropriate permissions
- Backup, recovery, and high-availability planning
- Storage for applications, updates, logs, packages, and database growth
Microsoft’s site-installation prerequisites should be treated as an implementation checklist rather than an optional reference.
Identity and cloud prerequisites
Requirements vary by design and may include Active Directory, Microsoft Entra ID, hybrid Microsoft Entra join, Microsoft Entra join, Intune enrollment, certificates, automatic enrollment, and appropriate administrator roles. Tenant attach also requires a functioning Configuration Manager administration service, a supported Azure environment, required outbound endpoints, and geographic alignment between the Azure tenant and service connection point.
Licensing
Configuration Manager is not free software and should not be reduced to a single retail monthly price. Licensing usually depends on Microsoft commercial agreements, product suites, user or device coverage, and applicable Software Assurance or equivalent rights. Microsoft states in its FAQ that customers licensed for Configuration Manager are also licensed for Intune to co-manage Windows PCs, subject to the applicable licensing terms.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Verify the exact entitlement through your Microsoft licensing agreement, Enterprise Agreement, Cloud Solution Provider, reseller, account team, or licensing specialist. Also budget for SQL, Azure consumption such as CMG usage, storage, administrators, application packaging, monitoring, upgrades, and disaster recovery.
Best Value
A practical modernization roadmap
- Assess: inventory sites, clients, applications, task sequences, collections, boundaries, distribution points, update rules, scripts, reports, identity states, and custom integrations.
- Stabilize: repair client-health problems, remove duplicate and inactive devices, validate content distribution, review boundaries, test recovery, and document customizations.
- Update: confirm a supported current-branch version, review the version-specific checklist, update the site and console, then update clients and validate applications, updates, operating-system deployment, reporting, and remote actions.
- Connect: select tenant attach, co-management, CMG, Endpoint analytics, or another cloud integration according to a defined objective. Do not enable every feature without reviewing identity, network, licensing, and workload implications.
- Pilot: use a representative collection containing laptops, desktops, remote devices, different Windows editions, important application groups, and ARM64 devices where relevant. Move one workload at a time.
- Operate: maintain a servicing calendar, monitor client health, review failed deployments and content status, keep boundaries current, test disaster recovery, and periodically reassess workloads for Intune.
Common failure modes
The client appears installed but is unhealthy
Investigate WMI, damaged client files, management-point assignment, boundary mismatches, certificates, tokens, DNS, proxies, stale policy, and duplicate records. Useful evidence includes client logs, Location Services, Policy Agent, ClientIDManagerStartup, ContentTransferManager, DataTransferService, UpdatesDeployment, ExecMgr, AppIntentEval, the CcmExec service, and controlled repair or reinstall actions.
Do not make client reinstallation the default fix. It can hide a boundary, identity, content, or policy problem.
Application deployment fails
Check detection methods, requirements, dependencies, supersedence, content distribution, user-versus-device targeting, maintenance windows, return codes, installation context, and whether the client’s boundary group has the content.
Free tools Windows power users keep installed
One-click scans. No signup required.
Updates do not install
Check software-update synchronization, update-group membership, deadlines, maintenance windows, scan source, WSUS health, restart behavior, third-party update configuration, and which product owns the Windows Update workload in a co-managed device.
Operating-system deployment fails
Review PXE and DHCP, boot-image drivers, network drivers, content availability, task-sequence variables, driver applicability, Secure Boot, firmware mode, disk partitioning, user-state migration, application return codes, and task-sequence logs.
CMG, tenant attach, or co-management fails
Check Azure permissions, the service connection point, certificates, DNS, firewall and proxy behavior, Microsoft Entra device state, automatic enrollment, outbound endpoints, supported versions, administrator permissions, and Intune licensing for the administrator signing in to the Intune admin center.
Security and governance
Configuration Manager should be operated as a privileged management system. Use role-based administration and least privilege, protect site servers and SQL, manage service accounts carefully, secure PKI and certificate trust, restrict internet endpoints, audit administrative activity, protect console extensions, and maintain tested backups and recovery procedures.
Pay particular attention to the Network Access Account. Microsoft’s 2603 changes strengthen its protections and recommend using the account only when necessary. CMG TLS behavior, SQL security, proxy rules, administrative roles, and separation of production from Technical Preview environments also deserve formal review.
Which management model should you choose?
| Requirement | Configuration Manager | Co-management | Intune-first |
|---|---|---|---|
| Complex Windows applications | Strong | Strong with planning | Validate requirements |
| Traditional imaging and task sequences | Strong | Retained where needed | Usually use Autopilot or another provisioning model |
| Internet-based devices | Requires CMG or additional design | Strong | Strong |
| Existing ConfigMgr investment | Best fit | Strong modernization path | Migration required |
| Mobile-device management | Limited compared with Intune | Intune handles mobile | Strong |
| Minimal infrastructure | Poor fit | Moderate | Strong |
| Gradual migration | Limited alone | Strongest | Requires migration planning |
Choose Configuration Manager when deep Windows management, local content control, complex deployment sequencing, or existing operational investment matters most. Choose co-management when you want a controlled transition to cloud services. Choose Intune-first when the organization is cloud-native, highly mobile, and willing to redesign provisioning and application delivery.
The commercial decision should compare total cost of ownership—not just license fees—including SQL, site servers, Azure usage, storage, staffing, packaging, migration, training, support, and operational risk.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

