I was wondering if there was a whitepaper or documented best practices for allowing users to connect to internal resources such as SCCM (formally SMS) and WSUS to retrieve policies for update and new configurations? I understand that we wouldn't be able to push configuration changes without Network Connect, but if the client side application calls back via WSAM.
I've tried a number of items including adding WSAM destinations (role level, resource level), added application executeables as passthrough, such as wuauclt.exe, ccmexec.exe, etc. with only success getting our AV to call back for updates. This seems like it would be a common issue in enterprise environments.
I spent a lot of time trying to get SMS working (as well as Kerberos) through WSAM but couldn't. If I remember correctly the SMS issue is a CLDAP (UDP) call which WSAM doesn't support. If not is was a DNS call for a service record which again WSAM didn't seem to be able to handle. The annoying thing for both Kerberos and SMS is it was just one packet that didn't get through.