Quantcast
Channel: Configuration Manager 2012 - Security, Updates and Compliance forum
Viewing all 6382 articles
Browse latest View live

Windows 10 on SCEP2012 installed?

$
0
0

Hello everybody,

Ihave the problem thatI can not install SCEP 2012onWindows10Enterprise.

TheWizardbelievesthat the applicationwas correct installed but I can notfindtheclient.WhentheWizardsendopenstheWindowsDefender.Hassomebodythe same problem?


THX


Failed software update returns error code 0x87D00668 - PART2

$
0
0
This is something which has already been discussed on Thread on year 2012- 

https://social.technet.microsoft.com/Forums/en-US/0a377ac1-f112-40a4-ad69-e2f1e66c5a5d/failed-software-update-returns-error-code-0x87d00668?forum=configmanagersecurity

But issue still persist and under discussion on Thread, Need help to get rid of this long going problem.

Raman Katoch TechNet Clean Energy

Push Endpoint Protection Update Definition to Clients

$
0
0

All,

I wish to push the "MPAM-fX64.exe" definition update to all my clients using SCCM 2012 R2.  I created a package, and deployed it, see below, but its not updating the laptops.

Can someone guide me on how to get my laptops to update using this push method?  I know about WSUS and all that, but that's not a solution I'm going to use.  Please focus your answer on how to push this out using SCCM 2012.

Thank you.


FreeRiderInNOVA

SCCM compliance to check firewall status

$
0
0

Hey guru's, 

I was wondering whether it would be possible to use SCCM compliance to check whether the Windows FW is enabled upon SCCM managed server infrastructure.

Our infrastructure is a mix of 2008 and 2012 OS. Any guidance appreciated. I just want a quick way to highlight those servers that have the FW disabled or the service not running. 

Kind regards. 



M Tipler

Windows 10 WindowsUpdate.log

$
0
0

Now that Windows 10 is released, I see that WindowsUpdate.log is still requiring that we run the Get-WindowsUpdateLog PowerShell command to convert ETW traces into a readable WindowsUpdate.log. I've long used  CMTrace for this file and wonder if any thought has been given to making it a bit easier to read the file for folks like us.


Orange County District Attorney

Granular permission for custom role in SCCM 2012.

$
0
0

Hi

We are users of SCCM 2012 and I have created 3 custom roles for our 3 IT teams to use.One of the teams are due to start deploying applications via SCCM, so I have updated their customised role so that they can do various application-related tasks.

However I cannot determine which permission will allow them to add a requirement for a deployment type (e.g. set the OS requirements for a deployment type). When they go into the deployment type > Requirements tab, the Add button is greyed out as shown in the attached screenshot.

Which permission would allow them to set this?

Thanks

Microsoft Edge updates

$
0
0

Hi Guys,

We have enable Windows 10 in the "Software Update point component properties ---> Products" then initiated a full sync from the SUP. For some reason  we are not able to see the updates for Microsoft Edge (MS15-091), looking at the wsyncmgr.log we can see the updates for Windows 10 but nothing for Edge.

Also there isn't anything related to Microsoft Edge in the Product categories.

Any idea?

Thanks

Clients rebooting after Software Update

$
0
0

Hi,

I'm hoping someone on here might have run into this issue before, I'm finding that some clients (not all) are rebooting after I deploy software updates to them. It always tends to be during the night when the PC idle. I see the message below in the event log.

In the deployment options I've set it to 'supress reboots' for clients and servers. I've also checked and none of the clients have a maintenance window set.

I've also seen that this can be caused by the WUA taking over so I've set this GPO to disabled:

Computer Policies\Administrative Templates\Windows Components\Windows Updates\Configure Automatic Updates >Disabled

What's strange is that after the reboot it brings back all of the applications it had open previously, almost like a recovery of some sort. Any ideas?

The process C:\Windows\system32\svchost.exe (PC_IT_Test) has initiated the restart of computer W7-IT-SW on behalf of user NT AUTHORITY\SYSTEM for the following reason: Operating System: Recovery (Planned)

Reason Code: 0x80020002

Shutdown Type: restart

Comment:



Windows Malicious Software Removal Tool x64 - August 2015 (KB890830) Download error

$
0
0

Get this error from the wsyncmgr.log when it tries to download the Windows Malicious Software Removal Tool x64 - August 2015 and Windows Malicious Software Removal Tool - August 2015

ailed to sync update fec9b910-402b-4f99-a2fe-81e9e505b7e3. Error: The Microsoft Software License Terms have not been completely downloaded and cannot be accepted. Source: Microsoft.UpdateServices.Internal.BaseApi.SoapExceptionProcessor.DeserializeAndThrow

SCCM2012 R2 SP1

All the others updates seem to have downloaded correctly, first time I have seen this error here.

Thanks.

Report after Patching Servers

$
0
0

I have been asked to supply a report of servers that have patched and then have it send an email to the application owner of what update applied and when and when the server rebooted etc...  By Server Name / Collection does anyone already have a custom report / process at their company doing something similar to this?

SCCM 2012 R2 SP1

Create configuration baseline for Windows services of service manager ? is that feasible !!

$
0
0

Hi Guys,

A quick question, can we create baseline configuration for the services in Windows service manager and i do need to remediate that also, please help if possible ?


Amit Singh Project Consultant (System center)


ADR operation aborted error message

$
0
0
I have an automatic deployment rule that ran last night, it's been running fine the past few months but this last time it ran an error message "operation aborted"  0x80004004.   I tried re-running it but I get this message  "You have initiated an action to run the selected rule.  When new software updates are found by the rule, the software updates will be added to the software update group specified in the rule."  Anyone know where I can find more info about this error and how to troubleshoot and get it to run without aborting?  Thanks.

SCCM 2012 SUP & WSUS DB Creation failed

$
0
0

I have SCCM 2012 SP1,  I am installing WSUS & SUP.  So, for to use SUP,  the prerequite is to install WSUS.  When I install WSUS, and try to connect to the same remote 2012 SQL server that SCCM has instance on,  

I get the following error:

Thank you for you help;

2013-05-08 15:11:50  Install type is: Fresh
2013-05-08 15:11:50  Creating database...
2013-05-08 15:11:51  Msg 262, Level 14, State 1, Server SCCM-SQL,  Line 2
CREATE DATABASE permission denied in database 'master'.
2013-05-08 15:11:51  Microsoft.UpdateServices.Administration.CommandException: Database creation failed
   at Microsoft.UpdateServices.Administration.ConfigureDB.CreateDatabase()
   at Microsoft.UpdateServices.Administration.ConfigureDB.Configure()
   at Microsoft.UpdateServices.Administration.PostInstall.Run()
   at Microsoft.UpdateServices.Administration.PostInstall.Execute(String[] arguments)
Fatal Error: Database creation failed

update is required for x number

$
0
0

System center 2012 R2 configuration manager  shows me that that update is required for x number.

how can I find out on what machines some update is required, is there some sql that I can use?

Thank you

Recommended process for upgrading to all the latest SCCM 2012 components

$
0
0

Hi guys,

I've got a SCCM 2012 SP1 CU4 server running on Windows 2008 R2.  I'd like to upgrade to all the latest updates.  From what I can tell that would be:

 - SCCM 2012 SP2 / Upgrade SCCM 2012 SP2 to SCCM 2012 R2 SP1

 - Cumulative Update 1 for System Center 2012 R2 Configuration Manager SP1 and System Center 2012 Configuration Manager SP2

 - Windows ADK 10 

I understand that to upgrade to SCCM 2012 SP2 I need to install the Windows ADK 8.1.  Can I just skip that step and jump right to the Windows ADK 10? 

If that's the case then I would assume the steps would be:

1. Uninstall the Windows ADK 8.0 from my SCCM 2012 server

2. Install the Windows ADK 10 on my SCCM 2012 server

3. Apply SCCM 2012 SP2 - reboot

4. Run SC2012_R2_SP1_Configmgr.exe to upgrade my SCCM 2012 SP2 server to SCCM 2012 R2 SP1

5. Apply Cumulative Update 1 for System Center 2012 R2 Configuration Manager SP1 and System Center 2012 Configuration Manager SP2

All done :)

Does this sound reasonable?

Thanks in advance.

Nick


OSD "Install Software Updates" in TS don't run during deployment, but it get publish some time after the deployment are finish.

$
0
0

OSD "Install Software Updates" in TS don't run during deployment, but it get publish some time after the deployment finished.

We have an OSD deployment of Windows Server 2012 R2, and I created an step in TS for "Install Software Updates" "All Software Update". I deployed the SUG to the OSD collection and it is available. The Software Updates start working some time after the OSD installation finished.

I created the Master image in MDT and run the Windows Update from Microsoft. I have an feeling that some old WUA settings is corrupted or old settings block the "Install Software Updates" in TS.

in wuahandler.log I can found this 

Tried to remove an update source ({749DB234-0AB0-4E94-9FEA-09DF65EBBE26}) that does not exist. WUAHandler 2015-08-13 14:42:56 1180 (0x049C)
Failed to Remove Update Source from WUAgent ({749DB234-0AB0-4E94-9FEA-09DF65EBBE26}). Error = 0x87d00691. WUAHandler 2015-08-13 14:42:56 1180 (0x049C)
CWuaHandler::SetCategoriesForStateReportingExclusion called with E0789628-CE08-4437-BE74-2495B842F43B;E0789628-CE08-4437-BE74-2495B842F43B,A38C835C-2950-4E87-86CC-6911A52C34A3; for leaves and E0789628-CE08-4437-BE74-2495B842F43B,A38C835C-2950-4E87-86CC-6911A52C34A3; for bundles WUAHandler 2015-08-13 14:44:11 3064 (0x0BF8)

How to fix this issue, so the OSD installation install the software update?


/SaiTech

Script is not Signed Error0x87D00327 While deploying configuration baseline

$
0
0

Hi Guys,

i am stuck in the issue where i am not able to deploy configuration baseline with some valid script ( manually checked on client & it is working) and for the Powershell execution policy i have also enable BYPASS in default client setting. DO i need to create Custom client setting for that.

your help will be appreciate with vote ;) 


Amit Singh Project Consultant (System center)

Server patching using CM12 R2 CU4

$
0
0

We are running CM12 R2 CU4 with one Primary and multiple secondary and standalone DP's (no CAS). Our infrastructure consists of approx. 11000 client machines and approx. 1200 servers.

Currently we use SCCM to manage only the workstations - no servers

Our server team now wants to utilize SCCM to patch and manage their servers... here is the "issue" I am encountering:

  • Approx 200 of these servers are 2003
  • the rest are 2008, 2012, and 2012 R2
  • The server team wants to manage their servers using the existing CM12 environment and ensure that my team CANNOT manage, access, patch the servers they are managing (my team all have FULL rights within SCCM)
  • The servers in question are in many different AD groups, some of which my team has full admin rights to those servers, BUT NOT the other groups

My questions:

  • Will CM12 R2 manage server 2003
  • how can I hand over a function of SCCM to the server team for only them to have access to, where myself and the rest of my team has no access and maintain full control everywhere else?
  • the server team wants to "build" out their own CM environment isolated from the production CM environment - I had advised against doing so due to conflicts with boundaries / subnets - is this possible?

Enforce Rstart In Winodws Update in SCCM 2012

$
0
0

Dears,

I have posted this issue before but didn't get the correct answer, and I will post it again hopefully some one can help me to find the solution, my case is I have almost 170 mix Windows server 2008 and 2012, and I wants to deploy windows updates through WSUS in SCCM 2012, I have created group package based on security updates and other requirement updates, and I deployed the updates package based on specific configuration which I selected required and automatic installation and restart the server after the installation completed, because I want to mention specific time which start and end date, I have used all the methods even windows maintenance in device collection, the updates will install automatically but message come after update it said restart required which is I have to do it manually I don't want restart manually I want the computer restart update finish automatically  because I can't login to 170 servers to restart servers manually, this see below snapshot, kindly any advice..

Disabling Software Update Deployments

$
0
0

The only place I see where I can disable a software update deployment prior to its creation is in the Automatic Deployment Rule wizard. Is there any other way of doing this other than first creating the software update deployment and then disabling it after it is created since it is enabled by default after it is created?

I am asking this because in my organization we have software update deployments that need to take place prior to others, so there are dependent deployments. Then once these deployments have a good success rate, we create others and deploy them, etc. I would like to create all deployments at one time and then just disable the ones that rely on others before it. I am am apprehensive of disabling after the deployment has been created because I am not sure how expedient the deployment will be and also not sure how quickly disabling the deployment will take affect when a collection of devices has been targeted. 

OR

Should I just create an empty collection and then target that, then once the deployment has been created, disable it?

Thanks

Viewing all 6382 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>