Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

For a Configuration Manager site system in an untrusted forest, enable Require the site server to initiate connections to this site system. This makes the trusted site server initiate Configuration Manager data-transfer connections to the remote site system, reducing the risk of a less-trusted server initiating connections into the trusted network. It does not create connectivity or fix DNS, firewall, account, SQL, certificate, or role-prerequisite problems.

Microsoft now calls the product Microsoft Configuration Manager; SCCM, ConfigMgr, and MEMCM remain common names for the same product lineage. The steps below concern a remote site-system role connected to a primary site. They do not make every role or topology supported: notably, a secondary site requires a two-way domain trust with its parent primary site.

What Configuration Manager means by an untrusted forest

A separate forest is not automatically an untrusted forest for every Configuration Manager decision. Microsoft’s security guidance distinguishes a domain in another forest that lacks a two-way forest trust with the site-server forest. A one-way or external trust is not the same as that required two-way forest trust. A domain in the same forest is a different case; so are a workgroup computer and a perimeter-network server, which may have no domain trust at all. Assess the actual trust type and authentication path rather than relying on the fact that a trust object exists. See Microsoft’s site-administration security guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The connection-direction option is particularly relevant for a perimeter system, an internet-facing site system, or a server in a forest that is not trusted. It is a security boundary control, not a way to make two forests trust each other.

#1 Best Overall
Sandisk 2TB Extreme Portable SSD, Up to 1050MB/s, USB-C, USB 3.2 Gen 2, IP65 Water and Dust Resistance, Updated Firmware, External Solid State Drive, SDSSDE61-2T00-G25
  • Get NVMe solid state performance with up to 1050MB/s read and 1000MB/s write speeds in a portable, high-capacity drive(1) (Based on internal testing; performance may be lower depending on host device & other factors. 1MB=1,000,000 bytes.)
  • Up to 3-meter drop protection and IP65 water and dust resistance mean this tough drive can take a beating(3) (Previously rated for 2-meter drop protection and IP55 rating. Now qualified for the higher, stated specs.)
  • Use the handy carabiner loop to secure it to your belt loop or backpack for extra peace of mind.
  • Help keep private content private with the included password protection featuring 256‐bit AES hardware encryption.(3)
  • Easily manage files and automatically free up space with the SanDisk Memory Zone app.(5). Non-Operating Temperature -20°C to 85°C

What the setting changes—and what it does not

When the option is not selected, a site system can initiate connections to the site server to transfer data. With the option selected, Configuration Manager data transfers are initiated by the site server from the trusted network. That helps prevent the remote, less-trusted server from initiating those connections into the trusted site network.

Do not interpret this as “all traffic is one-way” or “the remote server needs no outbound access.” A management point, distribution point, or software update point has role-specific communication needs. The remote server may still need to contact SQL Server, domain controllers, certificate-revocation endpoints, clients, or other services. The required flows depend on the role and design. Microsoft explains the security intent in its site-administration security and privacy documentation.

Set the connection direction in the console

  1. Open the Configuration Manager console.
  2. Go to Administration > Site Configuration > Servers and Site System Roles.
  3. Create the remote site-system server, or open its properties.
  4. On the General page, select Require the site server to initiate connections to this site system.
  5. For a target in an untrusted forest, specify the required Site System Installation Account.
  6. Add the required role and configure its role-specific communication settings.

For an existing server, check the option explicitly; do not assume it was selected when the server was first added. Microsoft’s documented untrusted-domain management-point example shows this setting and deployment flow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep the accounts separate by purpose

Site System Installation Account

For a server in an untrusted forest, the site server cannot rely on its computer account to authenticate to the remote server. Microsoft’s management-point example uses a Site System Installation Account for this boundary. Use an account that can be resolved and authenticated for the required remote administration, grant only the permissions needed for installation and administration, and protect it as a privileged credential. Test its use from the actual site server; a successful interactive sign-in somewhere else does not prove that the deployment path works.

Rank #2
Sandisk 1TB Portable SSD, Up to 800MB/s Read Speeds, Black (Old Model)
  • Solid state performance with up to 800MB/s read speeds in a portable drive. (Based on internal testing; performance may be lower depending on host device, interface, usage conditions and other factors. 1MB=1,000,000 bytes.)
  • Back up your content and memories on a storage solution that fits seamlessly into your mobile lifestyle.
  • Take it with you on your adventures—up to two-meter drop protection means this durable drive can take a beating. (Based on internal testing.)
  • Secure it to your belt loop or backpack for extra peace of mind thanks to the tough rubber hook.
  • From Sandisk, a brand professional photographers trust to take on assignments.

Role-specific accounts

A role may need a separate account for its own work. In Microsoft’s documented management-point example, the Management Point Connection Account accesses the Configuration Manager site database. That scenario grants the account a SQL login and the smsdbrole_MP and smsdbrole_MPUserSvc database roles. These are management-point-specific instructions, not blanket permissions for every remote site-system role. Follow the applicable role guidance rather than granting Domain Admin, Enterprise Admin, or SQL sysadmin by default.

Common account failures include using the site-server computer account across a boundary where it cannot authenticate, confusing the installation account with the management-point database account, using a trusted-forest account the remote server cannot reach, and overlooking local administration or service permissions on the target.

DNS, firewall, and authentication paths

Microsoft’s example management-point topology uses conditional forwarders in both forests so that each side can resolve the other forest’s fully qualified domain names. Test resolution from the machines that actually need it: the site server, remote site system, SQL Server, domain controllers, and clients. Check host records and, where relevant, reverse lookup and Kerberos service records such as _kerberos._tcp. A short-name lookup working does not prove that FQDN or KDC discovery works.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The following is the example connection list Microsoft gives for a management-point deployment, not a universal port recipe. Confirm source, destination, protocol, port, and business need for your own role and network design.

Rank #3
Sale
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
  • Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.
Source Destination Example protocol/port Purpose
Site server Remote management point TCP 135 RPC endpoint mapper
Site server Remote management point TCP 49152–65535 RPC dynamic ports
Site server and remote management point Each other TCP 445 SMB/file transfer
Remote management point SQL Server TCP 1433 SQL Server/site-database access
Site server Remote-domain controller UDP 389; TCP 88 CLDAP; Kerberos
Remote management point Trusted-domain controller UDP 389; TCP 88 CLDAP; Kerberos

These example ports may need adjustment for a named SQL instance or non-default SQL port, a restricted RPC dynamic-port range, the selected role, and the distinction between network and Windows Firewall rules. A role may also require IIS, client-facing, proxy, PKI, or certificate-revocation traffic not represented by this example. Consult the Microsoft deployment example and the current port guidance for the specific role before opening rules.

A trust, if present, is not proof that authentication works. Direction, forest versus external trust, name-suffix routing, selective authentication, account rights, DNS, and Kerberos can each block the actual request. Test the exact credentials and service path instead of treating trust status as a connectivity test.

Management-point deployment: SQL, IIS, and client security

In Microsoft’s documented untrusted-domain management-point example, the order is to prepare service accounts and SQL permissions, configure required network access, install Windows and IIS prerequisites, add the site-system server with its installation account and connection-direction option, then add the management-point role. The example supports choosing HTTPS or Enhanced HTTP for client communication according to the environment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not confuse the site-server-to-site-system connection direction with how clients authenticate to and communicate with the management point. For HTTPS, the management point needs an appropriate PKI web-server certificate bound to the IIS Default Web Site. Validate its subject or SAN against the management-point FQDN, private key access, certificate chain, revocation access, and client authentication requirements. Enhanced HTTP is not equivalent to a full PKI-backed HTTPS deployment; choose based on the intended Configuration Manager security model, not as a fix for a broken trust, firewall, SQL, or account path.

Rank #4
Sale
Sandisk 1TB Extreme Portable SSD, Up to 2000MB/s Transfer Speeds-New Model
  • NEARLY 2X FASTER THAN OUR PREVIOUS GENERATION(8) – move 1,000 high-res photos in under 60 seconds(6) with up to 2000MB/s transfer speeds(2).
  • IP65 RATING AND UP TO 3M DROP PROTECTION(3) – protects against spills and drops.
  • POCKET-SIZED – fits easily in pockets and small bags.
  • SPACE TO OWN YOUR AI CONTENT – speed and capacity to download your high-res clips and photo edits.
  • 256-BIT AES ENCRYPTION(4) – helps keep private files secure with password protection.

Clients in an untrusted forest or workgroup may not obtain the site-server signing certificate through Active Directory or ordinary client-push assumptions. Microsoft documents supplying the signing certificate during client installation with the SMSSIGNCERT property for relevant scenarios. Confirm the required certificate and installation method for your clients in Microsoft’s certificates overview. Certificate trust does not remove DNS, firewall, assignment, or management-point location requirements.

Role differences and a hard secondary-site limit

  • Management point: Check client reachability, IIS, site-database connectivity, domain-controller access where needed, authentication, and the chosen HTTPS or Enhanced HTTP configuration.
  • Distribution point: Content distribution and retrieval introduce content-library, SMB, remote-administration, and source-content paths. A pull distribution point has additional source and account requirements. Successful role installation alone does not prove that content transfer works.
  • Software update point: Add the relevant WSUS, IIS, SQL, synchronization, and certificate dependencies to the plan. Do not assume the management-point port matrix covers them.
  • Other roles: State migration points, fallback status points, and other site-system roles have their own prerequisites and flows; check the documentation for the specific role.

A remote site-system role connected to a primary site is not the same as installing a secondary site. Microsoft’s example states that secondary sites require a two-way domain trust with the parent primary site; a secondary site in a domain without the required trust is not supported. The checkbox does not waive that requirement. See the untrusted-domain deployment guidance.

Discovery is a separate workflow

A working management point does not prove that forest discovery or publishing works. Configuration Manager discovery methods contact domain controllers in the specified forest, and a secondary site cannot publish data to an untrusted forest. Diagnose these separately: can the site server resolve the forest, reach its domain controllers, and authenticate with the configured discovery account? Is the method expected to discover objects, publish data, or both in this topology? Review Microsoft’s discovery methods documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Troubleshoot in dependency order

  1. Confirm support and topology. Identify the role, whether the server is domain-joined or in a workgroup, the exact trust type, and whether this is a primary-site role or a secondary site. Stop if the chosen deployment is unsupported; the checkbox cannot change that.
  2. Verify the option. In the site-system server properties, confirm Require the site server to initiate connections to this site system is selected.
  3. Test DNS from both relevant sides. Resolve the site server, remote system, SQL Server, and domain controllers by FQDN. Check conditional forwarding and Kerberos SRV/KDC discovery, not just an isolated host lookup.
  4. Test the needed direction and ports. From the site server, test the remote server and required RPC, SMB, and role-specific endpoints. Separately test legitimate remote-server dependencies such as SQL or domain controllers. A successful TCP test to one port does not validate the entire role.
  5. Validate credentials independently. Check account format, status, lockout/expiry, remote local rights, and whether the site server can actually use the credential across the boundary. For SQL, verify the login, database mapping, and only the role-specific permissions required.
  6. Check role prerequisites and services. For an MP, verify IIS and SQL reachability; for a DP or SUP, test content or update-specific flows as well. Confirm firewall policy on both network devices and Windows hosts.
  7. Validate certificates and clients separately. Confirm IIS binding, certificate names, private key, chain and revocation reachability. If the role is healthy but clients fail, check client-to-MP DNS, assignment, ports, authentication mode, client certificate, and whether the client has the site-server signing certificate where required.
  8. Pinpoint the failing component in logs. Start with the site-server installation/role provisioning evidence and the remote role’s component logs; use IIS logs for MP web requests, SQL error logs for database failures, and client logs for location, policy, authentication, or certificate failures. For a DP, inspect the distribution and content-transfer component evidence. Log locations and filenames vary by component and version, so use Microsoft’s current Configuration Manager log-files reference to identify the right files. Correlate timestamps with DNS, Kerberos, firewall, and packet evidence rather than treating a single generic log as authoritative.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Common symptoms, interpreted correctly

“The option is selected, but installation fails”

Look for blocked site-server-originated RPC or SMB, unavailable dynamic RPC ports, failed FQDN or SRV resolution, unusable installation credentials, missing IIS or Windows prerequisites, SQL or database permissions, and invalid certificates where applicable. The setting controls initiation direction; it does not create these dependencies.

Best Value
Seagate Portable 5TB External Hard Drive HDD – USB 3.0 for PC, Mac, PS4, & Xbox - 1-Year Rescue Service (STGX5000400), Black
  • Easily store and access 5TB of content on the go with the Seagate portable drive, a USB external hard Drive
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

“The management point installed, but clients do not work”

Separate role installation from client operation. Check that clients can resolve and reach the MP, have the correct assignment and location, agree on HTTP versus HTTPS expectations, trust the presented certificate chain, satisfy client-authentication requirements, and can reach CRL/OCSP endpoints. Also verify delivery of the site-server signing certificate when the installation scenario requires it.

“Discovery fails, but clients communicate”

That can happen because discovery and client communication are distinct workflows. Validate discovery-account authentication and domain-controller access, and confirm that the chosen discovery or publishing method is supported for the forest relationship.

Choose the topology for the security boundary

If clients can reach a site system in the trusted forest and WAN performance is acceptable, keeping the role there may avoid cross-forest installation and account dependencies. If a remote role solves a concrete performance or network problem, deploy only the roles needed: every additional server and role expands the attack surface and firewall/account scope.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A two-way forest trust may simplify some authentication and discovery paths, but it changes the security relationship and is not a universal repair. Identity and security owners should assess whether it is acceptable. If the real requirement is managing clients across a boundary rather than hosting infrastructure in the remote forest, consider whether internet-based client management, cloud attach, Intune co-management, a separate hierarchy, or a dedicated management zone fits the organization’s architecture. These are design alternatives, not checkbox-level fixes.

Quick Recap

Bestseller No. 2
Sandisk 1TB Portable SSD, Up to 800MB/s Read Speeds, Black (Old Model)
Sandisk 1TB Portable SSD, Up to 800MB/s Read Speeds, Black (Old Model)
From Sandisk, a brand professional photographers trust to take on assignments.
$165.70
SaleBestseller No. 3
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$129.99
SaleBestseller No. 4
Sandisk 1TB Extreme Portable SSD, Up to 2000MB/s Transfer Speeds-New Model
Sandisk 1TB Extreme Portable SSD, Up to 2000MB/s Transfer Speeds-New Model
IP65 RATING AND UP TO 3M DROP PROTECTION(3) – protects against spills and drops.; POCKET-SIZED – fits easily in pockets and small bags.
$251.93
Bestseller No. 5
Seagate Portable 5TB External Hard Drive HDD – USB 3.0 for PC, Mac, PS4, & Xbox - 1-Year Rescue Service (STGX5000400), Black
Seagate Portable 5TB External Hard Drive HDD – USB 3.0 for PC, Mac, PS4, & Xbox - 1-Year Rescue Service (STGX5000400), Black
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$208.99

Preflight checklist

  • Identify the role and confirm the topology is supported; do not treat a secondary site like a remote site-system role.
  • Verify whether the relationship is a two-way forest trust, a different trust type, or no trust.
  • Select the site-server-initiation option and configure the required Site System Installation Account.
  • Resolve all required FQDNs and Kerberos records from the systems that need them.
  • Permit only role-specific, directional firewall flows; account for RPC range and SQL instance configuration.
  • Use separate, least-privilege accounts for installation and role-specific work; validate SQL rights only where required.
  • Choose HTTPS or Enhanced HTTP deliberately and validate certificates, revocation access, and client trust requirements.
  • Test the role from installation through its real workload: client communication, content transfer, update synchronization, or discovery as applicable.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.