diff --git a/memdocs/configmgr/core/clients/deploy/deploy-clients-cmg-token.md b/memdocs/configmgr/core/clients/deploy/deploy-clients-cmg-token.md index e29c9b0b67..ecc64f2e03 100644 --- a/memdocs/configmgr/core/clients/deploy/deploy-clients-cmg-token.md +++ b/memdocs/configmgr/core/clients/deploy/deploy-clients-cmg-token.md @@ -20,7 +20,7 @@ ms.reviewer: mstewart,aaroncz -The cloud management gateway (CMG) supports many types of clients, but even with [Enhanced HTTP](../../plan-design/hierarchy/enhanced-http.md), these clients require a [client authentication certificate](../manage/cmg/configure-authentication.md#pki-certificate). This certificate requirement can be challenging to provision on internet-based clients that don't often connect to the internal network, aren't able to join Microsoft Entra ID, and don't have a method to install a PKI-issued certificate. +The cloud management gateway (CMG) supports many types of clients, but the requirements can be challenging for internet-based clients that don't often connect to the internal network, aren't able to join Microsoft Entra ID, and don't have a method to install a PKI-issued certificate. To overcome these challenges, Configuration Manager extends its device support by issuing its own authentication tokens to devices. To take full advantage of this feature, after you update the site, also update clients to the latest version. The complete scenario isn't functional until the client version is also the latest. If necessary, make sure you [promote the new client version to production](../manage/upgrade/test-client-upgrades.md#promote-a-new-client-to-production).