Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
For a Configuration Manager site system in an untrusted forest, enable Require the site server to initiate connections to this site system. This makes the trusted site server initiate Configuration Manager data-transfer connections to the remote site system, reducing the risk of a less-trusted server initiating connections into the trusted network. It does not create connectivity or fix DNS, firewall, account, SQL, certificate, or role-prerequisite problems.
Microsoft now calls the product Microsoft Configuration Manager; SCCM, ConfigMgr, and MEMCM remain common names for the same product lineage. The steps below concern a remote site-system role connected to a primary site. They do not make every role or topology supported: notably, a secondary site requires a two-way domain trust with its parent primary site.
What Configuration Manager means by an untrusted forest
A separate forest is not automatically an untrusted forest for every Configuration Manager decision. Microsoft’s security guidance distinguishes a domain in another forest that lacks a two-way forest trust with the site-server forest. A one-way or external trust is not the same as that required two-way forest trust. A domain in the same forest is a different case; so are a workgroup computer and a perimeter-network server, which may have no domain trust at all. Assess the actual trust type and authentication path rather than relying on the fact that a trust object exists. See Microsoft’s site-administration security guidance.
The connection-direction option is particularly relevant for a perimeter system, an internet-facing site system, or a server in a forest that is not trusted. It is a security boundary control, not a way to make two forests trust each other.
#1 Best Overall
- Get NVMe solid state performance with up to 1050MB/s read and 1000MB/s write speeds in a portable, high-capacity drive(1) (Based on internal testing; performance may be lower depending on host device & other factors. 1MB=1,000,000 bytes.)
- Up to 3-meter drop protection and IP65 water and dust resistance mean this tough drive can take a beating(3) (Previously rated for 2-meter drop protection and IP55 rating. Now qualified for the higher, stated specs.)
- Use the handy carabiner loop to secure it to your belt loop or backpack for extra peace of mind.
- Help keep private content private with the included password protection featuring 256‐bit AES hardware encryption.(3)
- Easily manage files and automatically free up space with the SanDisk Memory Zone app.(5). Non-Operating Temperature -20°C to 85°C
What the setting changes—and what it does not
When the option is not selected, a site system can initiate connections to the site server to transfer data. With the option selected, Configuration Manager data transfers are initiated by the site server from the trusted network. That helps prevent the remote, less-trusted server from initiating those connections into the trusted site network.
Do not interpret this as “all traffic is one-way” or “the remote server needs no outbound access.” A management point, distribution point, or software update point has role-specific communication needs. The remote server may still need to contact SQL Server, domain controllers, certificate-revocation endpoints, clients, or other services. The required flows depend on the role and design. Microsoft explains the security intent in its site-administration security and privacy documentation.
Set the connection direction in the console
- Open the Configuration Manager console.
- Go to Administration > Site Configuration > Servers and Site System Roles.
- Create the remote site-system server, or open its properties.
- On the General page, select Require the site server to initiate connections to this site system.
- For a target in an untrusted forest, specify the required Site System Installation Account.
- Add the required role and configure its role-specific communication settings.
For an existing server, check the option explicitly; do not assume it was selected when the server was first added. Microsoft’s documented untrusted-domain management-point example shows this setting and deployment flow.
Keep the accounts separate by purpose
Site System Installation Account
For a server in an untrusted forest, the site server cannot rely on its computer account to authenticate to the remote server. Microsoft’s management-point example uses a Site System Installation Account for this boundary. Use an account that can be resolved and authenticated for the required remote administration, grant only the permissions needed for installation and administration, and protect it as a privileged credential. Test its use from the actual site server; a successful interactive sign-in somewhere else does not prove that the deployment path works.
Rank #2
- Solid state performance with up to 800MB/s read speeds in a portable drive. (Based on internal testing; performance may be lower depending on host device, interface, usage conditions and other factors. 1MB=1,000,000 bytes.)
- Back up your content and memories on a storage solution that fits seamlessly into your mobile lifestyle.
- Take it with you on your adventures—up to two-meter drop protection means this durable drive can take a beating. (Based on internal testing.)
- Secure it to your belt loop or backpack for extra peace of mind thanks to the tough rubber hook.
- From Sandisk, a brand professional photographers trust to take on assignments.
Role-specific accounts
A role may need a separate account for its own work. In Microsoft’s documented management-point example, the Management Point Connection Account accesses the Configuration Manager site database. That scenario grants the account a SQL login and the smsdbrole_MP and smsdbrole_MPUserSvc database roles. These are management-point-specific instructions, not blanket permissions for every remote site-system role. Follow the applicable role guidance rather than granting Domain Admin, Enterprise Admin, or SQL sysadmin by default.
Common account failures include using the site-server computer account across a boundary where it cannot authenticate, confusing the installation account with the management-point database account, using a trusted-forest account the remote server cannot reach, and overlooking local administration or service permissions on the target.
DNS, firewall, and authentication paths
Microsoft’s example management-point topology uses conditional forwarders in both forests so that each side can resolve the other forest’s fully qualified domain names. Test resolution from the machines that actually need it: the site server, remote site system, SQL Server, domain controllers, and clients. Check host records and, where relevant, reverse lookup and Kerberos service records such as _kerberos._tcp. A short-name lookup working does not prove that FQDN or KDC discovery works.
The following is the example connection list Microsoft gives for a management-point deployment, not a universal port recipe. Confirm source, destination, protocol, port, and business need for your own role and network design.
Rank #3
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
| Source | Destination | Example protocol/port | Purpose |
|---|---|---|---|
| Site server | Remote management point | TCP 135 | RPC endpoint mapper |
| Site server | Remote management point | TCP 49152–65535 | RPC dynamic ports |
| Site server and remote management point | Each other | TCP 445 | SMB/file transfer |
| Remote management point | SQL Server | TCP 1433 | SQL Server/site-database access |
| Site server | Remote-domain controller | UDP 389; TCP 88 | CLDAP; Kerberos |
| Remote management point | Trusted-domain controller | UDP 389; TCP 88 | CLDAP; Kerberos |
These example ports may need adjustment for a named SQL instance or non-default SQL port, a restricted RPC dynamic-port range, the selected role, and the distinction between network and Windows Firewall rules. A role may also require IIS, client-facing, proxy, PKI, or certificate-revocation traffic not represented by this example. Consult the Microsoft deployment example and the current port guidance for the specific role before opening rules.
A trust, if present, is not proof that authentication works. Direction, forest versus external trust, name-suffix routing, selective authentication, account rights, DNS, and Kerberos can each block the actual request. Test the exact credentials and service path instead of treating trust status as a connectivity test.
Management-point deployment: SQL, IIS, and client security
In Microsoft’s documented untrusted-domain management-point example, the order is to prepare service accounts and SQL permissions, configure required network access, install Windows and IIS prerequisites, add the site-system server with its installation account and connection-direction option, then add the management-point role. The example supports choosing HTTPS or Enhanced HTTP for client communication according to the environment.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Do not confuse the site-server-to-site-system connection direction with how clients authenticate to and communicate with the management point. For HTTPS, the management point needs an appropriate PKI web-server certificate bound to the IIS Default Web Site. Validate its subject or SAN against the management-point FQDN, private key access, certificate chain, revocation access, and client authentication requirements. Enhanced HTTP is not equivalent to a full PKI-backed HTTPS deployment; choose based on the intended Configuration Manager security model, not as a fix for a broken trust, firewall, SQL, or account path.
Rank #4
- NEARLY 2X FASTER THAN OUR PREVIOUS GENERATION(8) – move 1,000 high-res photos in under 60 seconds(6) with up to 2000MB/s transfer speeds(2).
- IP65 RATING AND UP TO 3M DROP PROTECTION(3) – protects against spills and drops.
- POCKET-SIZED – fits easily in pockets and small bags.
- SPACE TO OWN YOUR AI CONTENT – speed and capacity to download your high-res clips and photo edits.
- 256-BIT AES ENCRYPTION(4) – helps keep private files secure with password protection.
Clients in an untrusted forest or workgroup may not obtain the site-server signing certificate through Active Directory or ordinary client-push assumptions. Microsoft documents supplying the signing certificate during client installation with the SMSSIGNCERT property for relevant scenarios. Confirm the required certificate and installation method for your clients in Microsoft’s certificates overview. Certificate trust does not remove DNS, firewall, assignment, or management-point location requirements.
Role differences and a hard secondary-site limit
- Management point: Check client reachability, IIS, site-database connectivity, domain-controller access where needed, authentication, and the chosen HTTPS or Enhanced HTTP configuration.
- Distribution point: Content distribution and retrieval introduce content-library, SMB, remote-administration, and source-content paths. A pull distribution point has additional source and account requirements. Successful role installation alone does not prove that content transfer works.
- Software update point: Add the relevant WSUS, IIS, SQL, synchronization, and certificate dependencies to the plan. Do not assume the management-point port matrix covers them.
- Other roles: State migration points, fallback status points, and other site-system roles have their own prerequisites and flows; check the documentation for the specific role.
A remote site-system role connected to a primary site is not the same as installing a secondary site. Microsoft’s example states that secondary sites require a two-way domain trust with the parent primary site; a secondary site in a domain without the required trust is not supported. The checkbox does not waive that requirement. See the untrusted-domain deployment guidance.
Discovery is a separate workflow
A working management point does not prove that forest discovery or publishing works. Configuration Manager discovery methods contact domain controllers in the specified forest, and a secondary site cannot publish data to an untrusted forest. Diagnose these separately: can the site server resolve the forest, reach its domain controllers, and authenticate with the configured discovery account? Is the method expected to discover objects, publish data, or both in this topology? Review Microsoft’s discovery methods documentation.
Troubleshoot in dependency order
- Confirm support and topology. Identify the role, whether the server is domain-joined or in a workgroup, the exact trust type, and whether this is a primary-site role or a secondary site. Stop if the chosen deployment is unsupported; the checkbox cannot change that.
- Verify the option. In the site-system server properties, confirm Require the site server to initiate connections to this site system is selected.
- Test DNS from both relevant sides. Resolve the site server, remote system, SQL Server, and domain controllers by FQDN. Check conditional forwarding and Kerberos SRV/KDC discovery, not just an isolated host lookup.
- Test the needed direction and ports. From the site server, test the remote server and required RPC, SMB, and role-specific endpoints. Separately test legitimate remote-server dependencies such as SQL or domain controllers. A successful TCP test to one port does not validate the entire role.
- Validate credentials independently. Check account format, status, lockout/expiry, remote local rights, and whether the site server can actually use the credential across the boundary. For SQL, verify the login, database mapping, and only the role-specific permissions required.
- Check role prerequisites and services. For an MP, verify IIS and SQL reachability; for a DP or SUP, test content or update-specific flows as well. Confirm firewall policy on both network devices and Windows hosts.
- Validate certificates and clients separately. Confirm IIS binding, certificate names, private key, chain and revocation reachability. If the role is healthy but clients fail, check client-to-MP DNS, assignment, ports, authentication mode, client certificate, and whether the client has the site-server signing certificate where required.
- Pinpoint the failing component in logs. Start with the site-server installation/role provisioning evidence and the remote role’s component logs; use IIS logs for MP web requests, SQL error logs for database failures, and client logs for location, policy, authentication, or certificate failures. For a DP, inspect the distribution and content-transfer component evidence. Log locations and filenames vary by component and version, so use Microsoft’s current Configuration Manager log-files reference to identify the right files. Correlate timestamps with DNS, Kerberos, firewall, and packet evidence rather than treating a single generic log as authoritative.
Common symptoms, interpreted correctly
“The option is selected, but installation fails”
Look for blocked site-server-originated RPC or SMB, unavailable dynamic RPC ports, failed FQDN or SRV resolution, unusable installation credentials, missing IIS or Windows prerequisites, SQL or database permissions, and invalid certificates where applicable. The setting controls initiation direction; it does not create these dependencies.
Best Value
- Easily store and access 5TB of content on the go with the Seagate portable drive, a USB external hard Drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
“The management point installed, but clients do not work”
Separate role installation from client operation. Check that clients can resolve and reach the MP, have the correct assignment and location, agree on HTTP versus HTTPS expectations, trust the presented certificate chain, satisfy client-authentication requirements, and can reach CRL/OCSP endpoints. Also verify delivery of the site-server signing certificate when the installation scenario requires it.
“Discovery fails, but clients communicate”
That can happen because discovery and client communication are distinct workflows. Validate discovery-account authentication and domain-controller access, and confirm that the chosen discovery or publishing method is supported for the forest relationship.
Choose the topology for the security boundary
If clients can reach a site system in the trusted forest and WAN performance is acceptable, keeping the role there may avoid cross-forest installation and account dependencies. If a remote role solves a concrete performance or network problem, deploy only the roles needed: every additional server and role expands the attack surface and firewall/account scope.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →A two-way forest trust may simplify some authentication and discovery paths, but it changes the security relationship and is not a universal repair. Identity and security owners should assess whether it is acceptable. If the real requirement is managing clients across a boundary rather than hosting infrastructure in the remote forest, consider whether internet-based client management, cloud attach, Intune co-management, a separate hierarchy, or a dedicated management zone fits the organization’s architecture. These are design alternatives, not checkbox-level fixes.
Quick Recap
Preflight checklist
- Identify the role and confirm the topology is supported; do not treat a secondary site like a remote site-system role.
- Verify whether the relationship is a two-way forest trust, a different trust type, or no trust.
- Select the site-server-initiation option and configure the required Site System Installation Account.
- Resolve all required FQDNs and Kerberos records from the systems that need them.
- Permit only role-specific, directional firewall flows; account for RPC range and SQL instance configuration.
- Use separate, least-privilege accounts for installation and role-specific work; validate SQL rights only where required.
- Choose HTTPS or Enhanced HTTP deliberately and validate certificates, revocation access, and client trust requirements.
- Test the role from installation through its real workload: client communication, content transfer, update synchronization, or discovery as applicable.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

