Quantcast
Channel: Configuration Manager 2012 - Security, Updates and Compliance forum
Viewing all 6382 articles
Browse latest View live

SUP Synchronization between Server 2012 R2 and Server 2008 R2

$
0
0

Hi,

We have a SCCM environment (CAS and 4 Primary site servers) all Primary SUPs are in remote Box.

We are going to migrate the Server operating system starting from CAS server, so after i migrated the Server CAS OS from 2008 R2 to Server 2012 R2, will it work with the Primary SUPs which are on Server 2008 R2 boxes.


Machines is compliant without installing any updates

$
0
0

Hi All,

In our environment we have SCCM 2012 R2 SP1. We do server patch management using the same. We have noticed that some servers are showing patch complaint without even installing the patches. On one server last patches were installed in Nov 2015 after that no new patches have been installed.
I have tried to run software update cycles and checked log files but it shows 0 required patches.

Please suggest.

Updates Report says Compliant when no applicable updates are installed

$
0
0

Dear All,

             I am observing a strange behavior in a couple of Windows 2012 R2 and Windows 08 R2 servers.

Problem : When pushing out applicable updates on the said servers, the compliance report says the servers are compliant, however when i manually login to those servers and check, none of the applicable updates have installed.

I have SCCM 2012 R2 SP1.

Strangely, even the logs says nothing about it....All i find in the updatesdeployment.log is "Total actionable updates is 0" where infact there are many "actionable\applicable" updates present in the Update group i am pushing.

I also checked content versions using the below query..

select * from CI_UpdateCIs order by MinSourceVersion desc --> running this gives minsourceversion as 80

select * from wsusserverlocations--> running this gives sourceversion as 81

Any help would be highly appreciated. Thank you.

system center endpoint protection antivirus (Client) not updating from sccm primary server (SCCM 2012 r2)

$
0
0

I have implemented SCCM 2012 r2 Server (Primary Server) and enabled SCEP  with configured ADR (automatic deployment rule). ADR deployed on client collection. recently I found lots of machines showing "Active Client risk 1490" in SCEP dashboard and client SCEP showing unprotected mode. Can someone please help on this....




Thanks,

Prakash Kumar

why is windows update using http to download eula instead of https?

$
0
0

Hi,

After setting up SCCM 2012 R2 SP1 we are now moving the first clients to the new WSUS on SCCM instead of the old WSUS.

SCCM is configured to use https.

if I look at the windowsupdate.log on a 2008 client is see the client is connecting to wsus https (port 8531) but a few lines further its trying to download the eula file true http (port8530) which is blocked.

any guidance in why the client is trying over http instead of https?

part of the windowsupdate.log:

2016-06-2310:47:51:0061020a1cPT+++++++++++  PT: Synchronizing server updates  +++++++++++
2016-06-2310:47:51:0061020a1cPT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = https://SCCMserver.domain.local:8531/ClientWebService/client.asmx
2016-06-2310:49:21:0031020a1cPT+++++++++++  PT: Synchronizing extended update info  +++++++++++
2016-06-2310:49:21:0031020a1cPT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = https://SCCMserver.domaind.local:8531/ClientWebService/client.asmx
2016-06-2310:50:21:6711020a1cMiscWARNING: SendRequest failed with hr = 80072ee2. Proxy List used: <proxy.domain.local:8080> Bypass List used : <*.domain.com;*.domain2.local;*.domain3.local;*.domain4.local;*.domain5.local;10.*.*.*;<local>> Auth Schemes used : <>
2016-06-2310:50:21:6711020a1cMiscWARNING: WinHttp: SendRequestUsingProxy failed for <http://SCCMserver.domain.local:8530/Content/13/FDD2FEAEFCB08CF37AAAB589F1471FB5A41E1813.txt>. error 0x80072ee2
2016-06-2310:50:21:6711020a1cMiscWARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072ee2
2016-06-2310:50:21:6711020a1cMiscWARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072ee2
2016-06-2310:50:21:6711020a1cMiscWARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072ee2
2016-06-2310:50:21:6711020a1cAgentWARNING: Fail to download eula file http://SCCMserver.domain.local:8530/Content/13/FDD2FEAEFCB08CF37AAAB589F1471FB5A41E1813.txt with error 0x80072ee2
2016-06-2310:50:45:0241020a1cMiscWARNING: SendRequest failed with hr = 80072ee2. Proxy List used: <proxy.domain.local:8080> Bypass List used : <*.domain.com;*.domain2.local;*.domain3.local;*.domain4.local;*.domain5.local;10.*.*.*;<local>> Auth Schemes used : <>
2016-06-2310:50:45:0241020a1cMiscWARNING: WinHttp: SendRequestUsingProxy failed for <http://SCCMserver.domain.local:8530/Content/90/91A6A7BF92282F7E1C26D95FBB1C962C051BDE90.txt>. error 0x80072ee2
2016-06-2310:50:45:0241020a1cMiscWARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072ee2
2016-06-2310:50:45:0241020a1cMiscWARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072ee2
2016-06-2310:50:45:0241020a1cMiscWARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072ee2
2016-06-2310:50:45:0241020a1cAgentWARNING: Fail to download eula file http://SCCMserver.domain.local:8530/Content/90/91A6A7BF92282F7E1C26D95FBB1C962C051BDE90.txt with error 0x80072ee2
2016-06-2310:51:08:3461020a1cMiscWARNING: SendRequest failed with hr = 80072ee2. Proxy List used: <proxy.domain.local:8080> Bypass List used : <*.domain.com;*.domain2.local;*.domain3.local;*.domain4.local;*.domain5.local;10.*.*.*;<local>> Auth Schemes used : <>
2016-06-2310:51:08:3461020a1cMiscWARNING: WinHttp: SendRequestUsingProxy failed for <http://SERVERserver.domain.local:8530/Content/13/FDD2FEAEFCB08CF37AAAB589F1471FB5A41E1813.txt>. error 0x80072ee2
2016-06-2310:51:08:3461020a1cMiscWARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072ee2
2016-06-2310:51:08:3461020a1cMiscWARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072ee2
2016-06-2310:51:08:3461020a1cMiscWARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072ee2
2016-06-2310:51:08:3461020a1cAgentWARNING: Fail to download eula file http://SCCMserver.domain.local:8530/Content/13/FDD2FEAEFCB08CF37AAAB589F1471FB5A41E1813.txt with error 0x80072ee2

Compliance reporting inaccurate

$
0
0
I'm seeing an issue where workstations are showing up in the Overall Compliance report as Compliant, but, when I drill down to the individual machine the report is blank. Looking at the actual workstation, it is missing the previous month's patches.  This has me very concerned about the accuracy of the compliance report.  How many machines across our organization are reporting as compliant when in fact they are missing approved patched?

SUP Behaviour in Multi-SUP Site when Master SUP fails..

$
0
0

Hi, hope someone can help us with the following enquiry:

We have an SCCM 2012 environment with a Single Primary Site containing multiple Software Update Points (SUPs).

These SUPs are all sharing a single SUDSB database (as recommended by Microsoft), and this database is being synchronized from the external "Microsoft Update" location.

We have seen the anticipated behaviour that the first installed SUP becomes the "Master SUP", and is automatically configured to be the SUP which downloads changes from Microsoft. Any additional SUPs that we install configure themselves to Synchronize from the Master SUP - so what we see in the SCCM Console under Monitoring, Software Update Point Synchronization is:

- The first (Master) SUP has a Synchronization Source of "Microsoft Update".

- Any other SUPs have a Synchronization Source of the Master SUP.

Now, what we're trying to work out is what can happen from a recovery perspective if the Master SUP fails... I guess that could happen in a number of ways, but let's consider someone accidentally destroys the Virtual Machine on which it runs - with no backup of the disk images.. Here's a few questions -

1. As the Master SUP is no longer present, the other SUPs can't connect to it when they try to synchronize.. So what do they do? Do they just fail and continue failing forever, or does one of them somehow take over the role of the Master SUP and start synchronizing from Microsoft for the others?

2. (I guess this will change depending on the answer to 1), but how can we recover from this situation - i.e. if we build another Site Server (with or without the same name as the failed Master SUP, not sure?...), then can we force it to take over the activities of the previous Master SUP and carry on doing the synchronization? I guess this could depend on which (if any) of the other SUPs are acting as the Master SUP during the outage, as in that case we'd need to somehow re-point the synchronization activity from Microsoft to the newly built replacement machine, but I'm not sure how we'd do this - I don't believe there is anything in the SCCM Console allowing this to be configured...

We would be very grateful for any help and advice you could offer.

Many Thanks  

WSUSpool memory leak?

$
0
0

I recently had to rebuild the Software Update Point in our primary site.  I installed the WSUS and IIS server roles and then added the SUP role through the SCCM console.  The server was acting sluggish and I found that the w3wp.exe process associated with the WSUSPool application pool is constantly at 100% CPU and will eat memory until it gets to the recycle limit value.  I saw numerous threads about changing the recycle limit to higher than the default value but that just gives it more time until it recycles as it eats all that memory too.  Has anyone else seen this issue?


PowerShell script or command to get only updates showing as required

$
0
0

Good Day,

I am looking for a why to automate Software Updates in our environment utilizing CM12.

Our environment only approves, downloads, and deploys the updates that show as Required by client workstations.

When I search all software updates in the CM Admin Console I can create a saved search that uses the Required field being greater than 1.

When I use PowerShell a field that shows the Required data are not part of the returned object(s) when you use the Get-CMSoftwareUpdate cmdlet.

Is the required available through PowerShell?

SCCM 2012 R2 SP1 CU1(2) - Windows 10 ADK fails to offline service Windows 8.1

$
0
0

Hey, we upgraded to the Windows 10 ADK on our System Center Configuration Manager 2012 R2 SP1 CU1 (now CU2) servers. Since we did this upgrade, offline servicing no longer works for our Windows 8.1 images. Our Windows 10 and Windows 7 images offline service just fine.  Anyone else see this or have any ideas on how to fix this?  Thanks!

Here is the error from the OfflineServicingMgr log file:

Checking if update (2 of 20) with ID 16890813 needs to be applied on the image. 1 content binarie(s) are associated with the update. SMS_OFFLINE_SERVICING_MANAGER 11/5/2015 10:03:28 AM 10080 (0x2760)
dism.exe tool info: version=10.0.10240.16384, architecture=9 SMS_OFFLINE_SERVICING_MANAGER 11/5/2015 10:03:28 AM 10080 (0x2760)
Update applicability check is not supported. Dism.exe command line is below: SMS_OFFLINE_SERVICING_MANAGER 11/5/2015 10:03:41 AM 10080 (0x2760)
"C:\Windows\system32\cmd.exe" /q /c ""C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\amd64\DISM\dism.exe" /Image:"C:\ConfigMgr_OfflineImageServicing\01A000D1\ImageMountDir" /LogPath:%WINDIR%\Logs\Dism\dism_sccmAMD64.log /English /Get-PackageInfo /Packagepath:"C:\ConfigMgr_OfflineImageServicing\84cb9010-b27c-4962-ad44-9f5180f1fe3c\windows8.1-kb3074232-x64.cab">>C:\ConfigMgr_OfflineImageServicing\01A000D1\_@7DA8.tmp" SMS_OFFLINE_SERVICING_MANAGER 11/5/2015 10:03:41 AM 10080 (0x2760)
GetUpdateApplicability returned code 0x80070057 SMS_OFFLINE_SERVICING_MANAGER 11/5/2015 10:03:41 AM 10080 (0x2760)
Applicability State = APPLICABILITY_CHECK_NOT_SUPPORTED, Update Binary = C:\ConfigMgr_OfflineImageServicing\84cb9010-b27c-4962-ad44-9f5180f1fe3c\windows8.1-kb3074232-x64.cab. SMS_OFFLINE_SERVICING_MANAGER 11/5/2015 10:03:41 AM 10080 (0x2760)
Applying update with ID 16890813 on image at index 1. SMS_OFFLINE_SERVICING_MANAGER 11/5/2015 10:03:41 AM 10080 (0x2760)
dism.exe tool info: version=10.0.10240.16384, architecture=9 SMS_OFFLINE_SERVICING_MANAGER 11/5/2015 10:03:41 AM 10080 (0x2760)
Failed to install update with error code 87 SMS_OFFLINE_SERVICING_MANAGER 11/5/2015 10:03:54 AM 10080 (0x2760)
STATMSG: ID=7909 SEV=I LEV=M SOURCE="SMS Server" COMP="SMS_OFFLINE_SERVICING_MANAGER" SYS=server.mydomain.comSITE=01A PID=3480 TID=10080 GMTDATE=Thu Nov 05 16:03:54.969 2015 ISTR0="16890813" ISTR1="01A000D1" ISTR2="1" ISTR3="" ISTR4="" ISTR5="" ISTR6="" ISTR7="" ISTR8="" ISTR9="" NUMATTRS=0 SMS_OFFLINE_SERVICING_MANAGER 11/5/2015 10:03:54 AM 10080 (0x2760)
No need to apply this update binary since it's not required on the mounted image. SMS_OFFLINE_SERVICING_MANAGER 11/5/2015 10:03:54 AM 10080 (0x2760)

Exception in a compliance policy

$
0
0

Hello all,

As part of my operational compliance policy definition, I want to create a policy and deploy it to a set of servers. for ex:

I want to create a policy for a collection of windows servers to disable SMTP service on all of them but create an exception within the policy to identify the 'SMTP server' itself so the mail server can send emails while others shouldn't (perhaps a poor example to explain my scenario but I hope you understood where I want to go)

But while creating my compliance policy in sccm 2012, I did not find an option to create any kind of exception. I did some research and all I came across was firewall exceptions or something similar but even then, it was not done within the 'compliance settings' but rather in a GPO policy or other places.

Any help here? thanks

Question about compliance evaluation timing

$
0
0
I have a compliance baseline setup to check and make sure workstations have IE11 installed, if they don't then they are non-compliant.  This baseline is configured to evaluate every 30 mins on the workstations.  I have a collection setup which contains all the non-compliant machines from this baseline and a deployment task assigned to the collection that installs IE11 when a machine is added.

We have a good amount of users in the environment that are uninstalling IE11 to revert back to the previous browser.  So when they do this they will be placed in the non-compliant collection and have IE11 installed again.

Here's the problem.  Once they are placed in the non-compliant collection and have IE11 installed, after restarting, the compliance baseline doesn't evaluate again for up to 2 hours which would mark them as being compliant and remove them from the non-compliant collection.  This gives the user a large window to uninstall IE11 again reverting back to previous browser and, having never been removed from the non-compliant collection, they will not have IE11 reinstalled again.  I need for the baseline evaluation to occur right away on system restart so they can be removed from the non-compliant collection so that if they do uninstall IE11 again right away they will be added back to the collection thus causing the IE11 install task to kick off again.  Is there anyway to speed up the evaluation on client restart?

How to approve an update you previously expired in WSUS for SCCM?

$
0
0
I have an update, KB2882822, that I previously expired in WSUS and now need to make it available to deploy in SCCM.  Would I just go and change it to approved in WSUS console?  I notice all the other updates that are available in SCCM are in the "Not Approved" status but I see no way to change the status to Not Approved for KB2882822.  Thanks! 

CU5 Distribution Points?

$
0
0

Hopefully I'm in the right place.

I've applied CU5 to my 2012R2 Primary Site server successfully.  THe question is what do I do to update my separate distribution point?  It is listed in the console under \Administration\overview\site configuration \Servers and Site System Roles as a Site system server.

Do I run CM12-R2CU5-KB3054451-x64-ENU.exe on it OR Push the server update and console update packages, built by the CU5 wizard, to it?


# When I wrote this script only God and I knew what I was doing. # Now, only God Knows!

SCCM 2012 SUP Unable to Download Updates from Upstream WSUS

$
0
0
I have a customer that required an installation of SCCM 2012 with SUp.  The SQL 2008 R2 DB for SCCM is installed in a two node Active/Passive cluster as per the customers requirements.  The SUP component appears to be partially functional.  It will successfully synchronize with the upstream WSUS server operated by corporate but I cannot download or deploy any updates.  I would like to save approved updates locally to the SUP on a dedicated HDD.  However, if possible I do not want to download all updates, just those I specify.  Can someone please assist as I have not found anything in my searches of the internet for a possible solution to this issue.  Due to the security posture of the customer I cannot post entire logs, I can however post the text of any errors they may contain after obtaining the necessary approvals.

Configuration manager 2012 R2 - Suggested configuration for DBs

$
0
0

Hi Team,

I am setting up WSUS on different machine that configuration manager 2012 R2. While installing WSUS services from role and features on Windows server 2012 R2. I have few queries:

- What is the recommended practice for WSUS database with configuration manger 2012 R2? SQL Database or WID?

- What generally should be the criteria to choose between these 2 options WID or database ?

- Does WSUS supports SQL 2014 Express as its Database?

- What is the recommended database size for WSUS?

- What is the recommended database size for configuration manager 2012 R2 for around 1000 users/client machines?

- Does Configuration manager 2012 R2 supports 'Always On' with SQL failover cluster ?

Any pointers will be appreciated. Thanks

Regards, 

"Waiting to install" but updates are already installed

$
0
0
I have some updates that are stuck or at least showing "Waiting To Install" so I tried to install the updates manually and it said that they were already installed. How do I reset this or what do I do?

How to Enable Windows Update notifications (nag) when patching with SCCM 2012 R2

$
0
0

Hello,

In attempts to improve compliance with Microsoft Software Updates being deployed with ConfigMgr 2012 R2, I am looking to see if it is possible to enable Windows Updates reminder\notifications for Windows 7 machines.  Currently GPOs disable Windows Updates. Thanks

WSUS servers generating a lot of traffic and hitting network line

$
0
0

 Hello, guys

We have two WSUS servers with Software Update Point, which are generating a lot of traffic.

TCP    10.132.0.28:8530       10.24.5.137:60926      ESTABLISHED
  TCP    10.132.1.28:8530       10.24.12.76:57092      ESTABLISHED
  TCP    10.132.0.28:8530       10.24.146.35:54271     ESTABLISHED
  TCP    10.132.0.28:8530       10.32.131.12:54671     ESTABLISHED
  TCP    10.132.0.28:8530       10.32.132.240:56278    ESTABLISHED
  TCP    10.132.0.28:8530       10.32.134.59:52543     ESTABLISHED
  TCP    10.132.0.28:8530       10.32.194.74:58692     ESTABLISHED
  TCP    10.132.0.28:8530       10.32.196.108:53820    ESTABLISHED

For example we have 2Mbps network line to branch office and during synchronization clients hitting ~90% every working day and users are complaining about slow network.

Is it posible to reschedule updates after business hours?

Remove MS Updates from some workstations

$
0
0

Hi,

We are using SCCM 2012 R2, and Windows 7 sp1 for the workstations.

We discovered a windows update has caused a problem for a couple of workstations that access a https website, and if I manually uninstall it, the website logon page is displayed again.

Rather than exclude the update from being deployed to all workstations, I would rather remove it from the couple of PCs  and then update a flag on those workstations to say it has been installed, so SCCM will not make them available for installation again on those workstations.

Is this possible? I know you can do this with packages, but I guess with windows updates the PC will just do a wmi scan again and say it is not installed?

Thanks


Jaz

Viewing all 6382 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>