• Skip to primary navigation
  • Skip to main content
site logo
  • About
    • Approach
    • Partnerships
    • Mission
    • Leadership
    • Awards
    • Arraya Cares
  • Solutions
    • Solutions

    • Hybrid Infrastructure
      • Hyperconverged
      • Infrastructure as a Service
      • Servers, Storage, and Virtualization
      • Data Protection
      • Disaster Recovery & Business Continuity
    • Apps & Data
      • AI
      • Automation
      • Customizations
      • Visualizations & Integrations
      • Migrations
    • Network
      • Enterprise Networks
      • Wireless Connectivity
      • Cloud Networking Solutions
      • IoT
    • Cybersecurity
      • Endpoint Security
      • Network Security
      • Cloud Security
      • Application Security
    • Modern Workplace
      • Microsoft Licensing
      • Productivity & Collaboration
      • Modern Endpoint Deployment & Management
      • Microsoft Compliance & Risk
      • Backup
      • Cloud
  • Services
    • Services

    • Managed Services
      • Service Desk
      • Outsourced IT
      • Managed Security
      • Managed NOC
      • Arraya Adaptive Management for Microsoft Technologies
      • ADEPT: Arraya's White Label Program
    • Advisory Services
      • Assessments
      • Strategy
      • vCTO
      • vCISO
      • Enterprise Architecture
    • Staffing
      • Infrastructure Engineering
      • Security & Compliance
      • Application & Software
    • Professional Services
      • Project Management 
      • Systems Integration 
      • Mergers & Acquisitions
      • Knowledge & Skills Transfer 
  • Industries
    • Education
    • Finance
    • Healthcare
    • Legal
    • Manufacturing
    • Software and Services
  • Insights
    • News
    • Blog
    • Events
    • Videos
    • Case studies
  • Careers
  • CSP Login
search icon
Contact Us

Microsoft’s Cloud Management Gateway (CMG): 8 of Our Most Frequently Asked Questions

While some employees are slowly returning to the office, a generous portion of the workforce is still logging in remotely. In some capacity, remote work is here to stay indefinitely.  

As more companies become acquainted with a hybrid workforce, they’re often met with challenges related to managing their remote clients, enabling endpoint protection, distributing software, and more. With Microsoft’s Cloud Management Gateway, users can safely manage remote clients without exposing their on-premises infrastructure to the internet.  

So, what is Cloud Management Gateway?  

Cloud Management Gateway, or CMG for short, is a cloud extension of Microsoft Endpoint Configuration Manager that enables remote systems’ management without VPN (Virtual Private Networks) and without an extensive certificate requirement.  

Cloud Management Gateway FAQ’s:  

If you’re considering CMG for your business or organization, we’ve broken down the most frequently asked questions we receive so you know what to expect:  

  1. Do I need certificates? 

Yes, a trusted third-party certificate or public key infrastructure (PKI) certificates are required to create a secure communication between your on-premises Configuration Manager and the CMG resources that are primarily hosted in Azure. As far as the client certificates, plan to enable certificate enrollment for the workstations when domain joined. 

Please note that the use of certificates is less than a traditional SCCM Internet Based Computer Management (IBCM) configuration when using modern authentication and enhanced http in MECM (Microsoft Endpoint Configuration Manager). This configuration does not require that the management point be converted to operate only with https. 

  1. Where would a CMG get installed? 

The CMG is configured as a site system role, using the Configuration Manager console and with the use of an active Azure tenant. The resources used by the CMG are provisioned in the Azure cloud. 

  1. Are there fees associated with running the CMG? 

Yes, there are compute fees for the virtual machine scale sets and egress fees for non-Microsoft provided content. 

  1. Do I need an Azure Cloud subscription? 

Yes, there are Azure resources used for various purposes. In addition to authentication tokens provided by Azure AD (Active Directory), Intune integration with Microsoft Endpoint Configuration Manager (co-management) is highly recommended but not required.  

  1. Which version of Configuration Manager is required?  

2107 (July 2021 release) or later, is required to support the current features and deployment practices for the CMG. 

  1. What is enhanced http or e-http?  

E-http allows you to secure sensitive client communication without the need for PKI server authentication certificates. Clients can securely access content from distribution points without the need for a network access account, client PKI certificate, or Windows authentication.  

  1. Do I still need a split-tunnel VPN configuration for my Microsoft content?  

Yes. To keep the costs down when utilizing Azure stored content and make this fully independent of on-premises content, this configuration is recommended to allow Microsoft edge content locations to download the content when connected to VPN. Microsoft related content provided in this configuration is not billed as egress when servicing internet-based clients. 

  1. How does this change my non-Microsoft content delivery?  

When completely disconnected, the client will negotiate the state and switch to internet managed. Internet managed devices are configured to get Microsoft updates through Microsoft resources. As far as non-Microsoft content is concerned, the client will be able to only get content that is distributed to the CMG Servers in Azure, also known as a Virtual Machine Scale Set.  

Next Steps: Enhance Your Remote Environment 

CMG provides users with a straightforward way to manage Configuration Manager clients remotely so clients can seamlessly access on-premises site roles whether on the intranet or internet. As the workforce continues to rapidly change, it’s important that your business takes advantage of the latest means to support your employees.  

For more information on Cloud Management Gateway, contact an Arraya expert today to start a conversation.  

Visit https://www.arrayasolutions.com//contact-us/ to connect with our team now. 

Comment on this and all of our posts on: LinkedIn, Twitter and Facebook.     

Follow us to stay up to date on our industry insights and unique IT learning opportunities.    

Arraya Insights
Back to Top
Arraya Solutions logo

We combine technological expertise and personal service to educate and empower our customers to solve their individual IT challenges.

518 Township Line Road
Suite 250, Blue Bell, PA 19422

p: (866) 229-6234     f: (610) 684-8655
e: info@arrayasolutions.com

  • Careers
  • Privacy Policy
  • Contact Us

© 2025 Arraya Solutions. All rights reserved.

Facebook Twitter YouTube LinkedIn
Manage Cookie Consent
We use cookies to enhance your experience. By selecting “Accept,” you agree to our cookie policy.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}