--- title: High-Level Architecture of MBAM 2.5 with Configuration Manager Integration Topology description: High-Level Architecture of MBAM 2.5 with Configuration Manager Integration Topology author: jamiejdt ms.assetid: 075bafa1-792b-4c24-9d8e-5d3153e2112c ms.pagetype: mdop, security ms.mktglfcycl: manage ms.sitesec: library ms.prod: w10 ms.date: 07/18/2017 --- # High-Level Architecture of MBAM 2.5 with Configuration Manager Integration Topology This topic describes the recommended architecture for deploying Microsoft BitLocker Administration and Monitoring (MBAM) with the Configuration Manager Integration topology. This topology integrates MBAM with System Center Configuration Manager. To deploy MBAM with the Stand-alone topology, see [High-Level Architecture of MBAM 2.5 with Stand-alone Topology](high-level-architecture-of-mbam-25-with-stand-alone-topology.md). For a list of the supported versions of the software mentioned in this topic, see [MBAM 2.5 Supported Configurations](mbam-25-supported-configurations.md). **Important** Windows To Go is not supported for the Configuration Manager Integration topology installation when you are using Configuration Manager 2007. ## Recommended number of servers and supported number of clients The recommended number of servers and supported number of clients in a production environment is as follows:
Recommended architecture | Details |
---|---|
Number of servers and other computers |
Three servers One workstation |
Number of client computers supported |
500,000 |
Configuration Manager version | Description |
---|---|
System Center 2012 R2 Configuration Manager System Center 2012 Configuration Manager |
If you install MBAM on a primary site server or on a central administration server, MBAM performs all of the installation actions on that site server. |
Configuration Manager 2007 R2 Configuration Manager 2007 |
If you install MBAM on a primary site server that is part of a larger Configuration Manager hierarchy with a central site parent server, MBAM identifies the central site parent server and performs all of the installation actions on that parent server. The installation includes checking prerequisites and installing the Configuration Manager objects and reports. For example, if you install MBAM on a primary site server that is a child of a central site parent server, MBAM installs all of the Configuration Manager objects and reports on the parent server. If you install MBAM on the parent server, MBAM performs all of the installation actions on that parent server. |
Items installed into Configuration Manager | Description | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
Configuration data |
The configuration data installs a configuration baseline, called “BitLocker Protection,” which contains two configuration items:
The configuration baseline is deployed to the MBAM Supported Computers collection, which is also created when MBAM is installed. The two configuration items provide the basis for evaluating the compliance status of the client computers. This information is captured, stored, and evaluated in Configuration Manager. The configuration items are based on the compliance requirements for operating system drives and fixed data drives. The required details for the deployed computers are collected so that the compliance for those drive types can be evaluated. By default, the configuration baseline evaluates the compliance status every 12 hours and sends the compliance data to Configuration Manager. |
||||||||||
MBAM Supported Computers collection |
MBAM creates a collection that is called MBAM Supported Computers. The configuration baseline is targeted to client computers that are in this collection. This is a dynamic collection. By default, it runs every 12 hours and evaluates membership, based on three criteria:
The collection is evaluated against all computers and a subset of compatible computers is created, which provides the basis for compliance evaluation and reporting for the MBAM integration. |
||||||||||
Reports |
When you configure MBAM with the Configuration Manager Integration topology, you view all reports in Configuration Manager, except the Recovery Audit Report, the latter of which you continue to view in the MBAM Administration and Monitoring Website. The reports available in Configuration Manager are:
|