Quantcast
Channel: Configuration Manager 2012 - Security, Updates and Compliance forum
Viewing all 6382 articles
Browse latest View live

adding read only user

$
0
0

Dear,

i need to add new user who will have permissions just to see collections..
I add in security role new role which have all read parameters, add user in that role and rest seems fine, but problem is that we cannot start console, getting:

"configuration manager cannot connect to the site" (cannot upload image due to account restriction)

where i am wrong?

tnx.


Clients not communicating with SCCM

$
0
0

We have just deployed SCCM and are attempting to deploy MS updates with it however the clients do not appear to be communicating with SCCM.  We have specified an intranet server via a GPO ofhttp://....:8530.  Where can I begin to look to identify the issue?  Not sure what the log files are within SCCM.

All machines are showing Client check passed/Active but are UNKNOWN for update status. Help please! :)

$
0
0

Howdy,

SCCM 2012 R2, Windows 10, Server 2012 R2.

All of a sudden, starting in August, all of our machines in SCCM are showing as Client check passed/Active when I check my software update groups for Windows Patches.  Prior to this we were always around 80% compliance and for August and September it shows 0% because everything is Unknown.  This is happening for our servers and laptops.

What's the best way to figure out what the problem is here as this just seemed to come out of no where.

Let me know what other information I can provide and I'll post it right away.

Thanks


SMS Writer Not found in VSS admin List writers

$
0
0

SCCM backup failed on the primary server. when checking the VSS admin List writers, only SMS writer is missing. Restarted the SMS_Site_VSS_Writer service. Also restarted the standalone primary server once. But sms writer not yet listed .      

SMSBKP.log 

Error: SMS Writer service either does not exist or is not running .SMS_SITE_BACKUP28-09-2016 19:37:418616 (0x21A8)
Error: GatherWriterMetadata failed.SMS_SITE_BACKUP28-09-2016 19:37:418616 (0x21A8)
SMS_SITE_BACKUP failed. Please see previous errors.SMS_SITE_BACKUP28-09-2016 19:37:418616 (0x21A8)
Raised backup task failure alert.SMS_SITE_BACKUP28-09-2016 19:37:418616 (0x21A8)

smswriter.log 

SMS_SITE_VSS_WRITER 0 0 - starting to build the metadata.SMS_SITE_VSS_WRITER28-09-2016 19:37:3710200 (0x27D8)
Error: Failed to inlcude E:\PROGRAM FILES\MICROSOFT CONFIGURATION MANAGER\BIN into the metadata.SMS_SITE_VSS_WRITER28-09-2016 19:37:3710200 (0x27D8)
Successfully included E:\PROGRAM FILES\MICROSOFT CONFIGURATION MANAGER\ADMINUICONTENTSTAGING into to the metadata.SMS_SITE_VSS_WRITER28-09-2016 19:37:3710200 (0x27D8)
Successfully included E:\PROGRAM FILES\MICROSOFT CONFIGURATION MANAGER\INBOXES into to the metadata.SMS_SITE_VSS_WRITER28-09-2016 19:37:3710200 (0x27D8)
Successfully included E:\PROGRAM FILES\MICROSOFT CONFIGURATION MANAGER\LOGS into to the metadata.SMS_SITE_VSS_WRITER28-09-2016 19:37:3710200 (0x27D8)
Successfully included E:\PROGRAM FILES\MICROSOFT CONFIGURATION MANAGER\DATA into to the metadata.SMS_SITE_VSS_WRITER28-09-2016 19:37:3710200 (0x27D8)
Successfully included E:\PROGRAM FILES\MICROSOFT CONFIGURATION MANAGER\SRVACCT into to the metadata.SMS_SITE_VSS_WRITER28-09-2016 19:37:3710200 (0x27D8)
Successfully included e:\Program Files\Microsoft Configuration Manager\install.map into to the metadata.SMS_SITE_VSS_WRITER28-09-2016 19:37:3710200 (0x27D8)
Building meta data failed.SMS_SITE_VSS_WRITER28-09-2016 19:37:3710200 (0x27D8)

WSUS Registry value shows primary site server instead of secondary SUP

$
0
0
We have a environment with a SCCM 2012 R2 primary site and multiple secondary sites. WSUS Registry entry of the client machines in the secondary site server location are showing "http://Primaryserver.domain.com:8530" instead of "http://Secondaryserver.domain.com:8530". Even if manually update the registry with secondary server name its getting modified when i initiate the software update scan on the client machine. As i verified there is no any group policy applied on the location OU for this. Please assist on what could be the issue, because of this software update scan getting failed on the machines. 

Failed to set Subscriptions on the WSUS Server. Error:(-2146233088)Unknown error 0x80131500 in SCCM 2012 Sp1 with Windows 2012 R2

$
0
0

Hi All,

I have installed SCCM 2012 Sp1 on Windows 2012 R2, now configured WSUS and added SUP, now it is not synchronizing updates, giving mentioned error


Kirpal Singh

Workstation Client in Secondary Site Pulling Updates From SUP in Primary Site

$
0
0

Hello all,

We have a Config Manager 2012 deployment with a Primary Site for North America with two management points (SCCM04 and SCCM05) and one Software Update Point (SCCM05). We have a Secondary Site for Asia, with one management point (HKSCCM010). We've had an issue where clients in the Secondary Site are pulling content from the SUP in the primary site, rather than their local DP.

My question is, is there a particular log file on the Software Update Point I can look at to see what content a particular client is downloading? Because the client is in Asia, it's not usually available during normal working hours as they power off after hours. What makes it even more difficult is that each night it appears to be different clients, not necessarily the same client everytime.

Any help is greatly appreciated. We've opened a case with Microsoft and configured everything according to their best practices, but still seem to have this issue ongoing.

Thanks,

Joel

Feature update to Windows 10 Enterprise version 1607 keeps failing on all client machines

$
0
0
Good day,
Has anyone perhaps had the same issue where the Feature update to Windows 10 version 1607 fails on the client machines.
 I have had some feedback from various Forums suggesting that we add .esd to the MIME TYPE
Infrastructure updated.
Is there perhaps something that we might have missed or any suggestions.

October Month security Updates: is Security only Quality update included with dot net updates?

$
0
0
we usually do not deploy Dot net updates to some application servers. so here we need to exclude Dot net updates and deploy only monthly security updates. So could someone help me to understand whether Dot net is included in  "Security only Quality update" or not? if included then why we have separate  "Security only update for Dot net" update . Thank you. 

Systems still show vulnerability after update KB3188744 Security update for .Net 4.5

$
0
0

My customer just did a round of patching for servers. One group updated over the weekend and another group was patched last night. The second group installed KB3188744 (Security Update for .NET Framework 4.5...), but not KB3074550 because it was superseded (and expired) by 3188744. After a vulnerability scan the second group of servers did not have the newest system.dll, system.xml.dll, or system.drawing.dll. Shouldn't the superseding update have included those?

Is anyone else seeing this problem? If so, what are you doing to remedy it?

Thanks.

error

$
0
0

how to reslove this problem  0x80131500

remediation question

$
0
0

I've read some threads about this but if you check the remediation box on your baseline should it reinstall software if its found out of compliance?   If "yes" how/where do you tell it which package/application to reinstall?   


mqh7

Monthly Patches freeze on Stage 2 of 2 Preparing to Configure Windows

$
0
0
October 2016 patches deployed to workstations (Win 7).  Patches seem to install fine but the workstations freeze at Stage 2 of 2.  Can control alt delete to login screen and systems come up fine.  We have SCCM 2012 R2.

Windows 10 updates is blank

$
0
0

Hello,

I'm having this weird problem where I can see Windows 10 updates in the "All Software Updates" node, but when I go to the Windows10 Servicing -> "All Windows 10 Updates" node, it's empty.

I've scoward the Interwebs on this issue, but can't find anything.

I'm trying to update my Windows 10 machines, but it doesn't seem to want to update via "Automatic Deployment Rules"

wsyncmgr.log doesn't show any errors whatsoever when I click on "Synchronize software updates" button

Software Update Center empty in trusted domains

$
0
0

Hello.

In our environment we have a single site managing multiple subnets and three domains (all two-way trusts).  The client installed perfectly fine, getting inventories, pushing policies all works fine.  Weird part is Software Update Center only shows updates in the domain that the SCCM server is in.  In the other two domains, it's empty.

Any ideas would be greatly appreciated.

Thank you.


Uninstall Cumulative Update 3

$
0
0
we recently install CU3 on SCCM 2012 R2 Sp1 primary site. we are having issue some like updating sccm client, sccm still fetching old has value

File 'C:\Windows\ccmsetup\SCEPInstall.exe' with hash 'AE71ED1F26ED5CAE468E556E2983D5237805A67808EDFB058535D69F993E7597' from manifest doesn't match with the file hash '053213C962817ECFF8819B592547355CA0EB15381BD999E19EF9396754D11B47'          ccmsetup            10/21/2016 12:15:12 PM         3144 (0x0C48)

it could be possible to uninstall CU3 from server ?or any other solution to fix that issue 


Seeing an error "None of the applications you tried to install began installation successfully" when trying to run an update from Software Center

$
0
0

Can someone please help me understand why this error occurs?

Thank you all

How do I remove a deployment that no longer has a name?

$
0
0

I managed to get my SCCM server into a state where I now have a Software Deployment that no longer has a name as you can see in the screen grabs below.  The question now is, how do I get rid of this as I believe it is causing havoc.  By that I mean several things with WSUS are no longer working on the server and all Windows update processing has come to a halt.  In case it matters, this deployment was initially for an Office 365 client patch.




Mike...

Configuration Items & SCCM Client Options

$
0
0

Hello everyone,

In Software Center, Options there's an option that I'd like to enable via script - Automatically install or uninstall required software and restart...

I've found such script that allows me to enable this option. I'd like to deploy this as a Configuration Item, so here's my question: will this code go in the Discovery script section or the Remediation script (optional) section?

I tried it as part of the Discovery script section, I've waited over 12 hours and none of the clients have this option enabled.

If I run the script on my computer, the script runs and enables the option, so I know the script works fine.

Here's the script that I'm talking about:

' Sets WMI environment
Set objUX = GetObject("winmgmts:\\.\root\ccm\ClientSDK:CCM_ClientUXSettings")

' Setting environment for method getAutoInstallRequiredSoftwaretoNonBusinessHours
Set inParam = objUX.Methods_.Item("setAutoInstallRequiredSoftwaretoNonBusinessHours").inParameters.SpawnInstance_()

' Change value of property to ‘True’ (checked)
inParam.AutomaticallyInstallSoftware = True

' Set value for property from client
Set result = objUX.ExecMethod_("setAutoInstallRequiredSoftwaretoNonBusinessHours", inParam)

Thanks!

MS patch 3042058 is getting reflected for installation after Sep 2016 patch is deployed

$
0
0

Hi

It is quite strange that after I deployed Security update patch for September 2016 , observed that Patch 3042058 belonging to  Oct 2015 security patch got reflected automatically. Although we had 100% compliance in Nov 2015.

Viewing all 6382 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>