Quantcast
Channel: Configuration Manager 2012 - Security, Updates and Compliance forum
Viewing all 6382 articles
Browse latest View live

SCCM Windows updates: stuck on "downloading", howto reset client?

$
0
0

Hi,

We have some clients which give an error on installing Windows updates in SCCM.

I'd like to find out why it can't download (only 6 from 600 pc's had this error), however I would like a quickfix more = what could I do to enforce this?

Please advise,
J.

Error = 


Jan Hoedt


Windows Updates (post SCCM upgrade)

$
0
0

Hello,

Recently we upgraded our environment from 2012 SP1 to 2012 R2 SP1 CU3 and for the most part everything has worked as expected with the exception of Windows Updates.  Prior to the upgrade Windows Patches downloaded and installed relatively quick, but since the upgrade Windows Patches take a very long time to download and install.  It use to take approximately 4-6 hours for packages and patches to get deployed to a new image and now that same workstation will quickly install the packages required, but get seemingly hung at downloading updates or installing updates for every single KB listed in Software Center. 

They eventually all download/install, but it just takes a ridiculous amount of time (1 day).  So far no logs seem to indicate an issue as they eventually all install successfully, but if there is anything I can check it would be appreciated.

Thanks,

Blind 

All machines are showing Client check passed/Active but are UNKNOWN for update status. Help please! :)

$
0
0

Howdy,

SCCM 2012 R2, Windows 10, Server 2012 R2.

All of a sudden, starting in August, all of our machines in SCCM are showing as Client check passed/Active when I check my software update groups for Windows Patches.  Prior to this we were always around 80% compliance and for August and September it shows 0% because everything is Unknown.  This is happening for our servers and laptops.

What's the best way to figure out what the problem is here as this just seemed to come out of no where.

Let me know what other information I can provide and I'll post it right away.

Thanks


How to check the Software Update Deployment Available time applied to Client in SCCM 2012 SP2

$
0
0

Hi ,

I deploy Software Update group of Server 2008 R2 and Server 2012 R2 Patches to one Device Collection  today (27-10-16) with Software Available Schedule as 28/10/2016, 10:30 AM and installation deadline schedule as 28/10/2016, 12:30 PM . to start the deployment from 12:30 PM local time on-wards..

but i want to make sure about these software available and deadline schedule for the clients .. can i see such scheduled time policy applied to clients in any logs or any other way to check this available time configuration for clients to whom we actually deploy this updates... (before such Software available visible in Software Center at actual software available time)?



Shailendra Dev

Some updates are showing under Show Optional Software in Software Center

$
0
0

Hi,

I am deploying patches to Windows Server OS Quarterly with deployment purpose as Required with below process:

1. filter the patches with Security,Critical and normal updates, create Software update group for each Server OS.

2. deploy Each Server OS SUG to each Sever OS Device Collection.

I observer, on some server`s software center >Available Node, there are many Updates,security updates are showing asoptional Software as below:

I want to know why this updates are showing as Optional Software.. what exactly means of showing this way.. is this means these updates will not deployed by SUG that i already deployed to OS Device Collection? How can i solve this?

I am using SCCM 2012 SP2.


Shailendra Dev

SCCM 2012 R2 - Manage-bde command not working with the Baremetal TS

$
0
0

Hi All,

I have a site with SCCM 2012 R2 using which I am trying to deploy baremetal machines. At the end of the TS I have a step to encrypt the drive using manage-bde command. A bitlocker GPO is set in the AD for these machines which has settings to save the recovery key in AD. The TS runs fine on the devices the manage-bde command runs fine & do the encryption but it does not save the key to AD. I validated and found the GPO's are applied correctly.

SMSTS.log shows that the manage-bde step ran fine & the status of deployment in SCCM Console shows the same.

Test 1 - I tried to just run the manage-bde step by putting it in a separate custom task sequence & this time it ran fine saving the key to AD.

What can be possible reason for this. Please help.

Thanks,

Pranay. 

Upgrading clients from 5.00.8325.1000 to 5.00.8412.1007 not working

$
0
0

We are upgrading certain our environment from 1511 to 1607 Windows 10 anniversary edition through SCCM... Went through and updated our SCCM site server to 1606. No problems on the upgrade as far as i know. At the end of the install the installation asked if I wanted to install the upgrade agent on all machines in the site or a subset of our environment. I chose to only upgrade the administrators container for testing.

Now, I have been trying to update the SCCM Agent from (5.00.8325.1000) which was the old agent to (5.00.8412.1007), the new agent. I am doing a manual install, (launching ccmexec.exe on the client machine) but when i try install the agent the agent doesn't get updated.

The control panel applet is still is at (5.00.8325.1000.) I've tried installing as an administrator, my domain admin account, removing the agent using ccmclean, and reinstalling, but the applet is still shows up as the old agent

Any one else having this problem?

I sort of remember having this issue with upgrading from 2003 to 2007 but i can't remember the solution.

Seem to me that once the ccmsetup install starts; the installation reaches out to the SCCM site server for components and downloads the old components (maybe, it don't know) again. So I am really stumped here.

Not sure if the agent needs to be upgraded for the "1607 Upgrade", but through testing once the agent gets installed, seems to me the "Upgrade" gets installed easier than with the old components. So far there have been three out of four"Upgrades" once the agent gets installed.. still testing... (Want to test this further but if i can install the upgraded agent I can't be certain.)

But the main thing is how how i get the agent to install and why it it experiencing the behavior. Any one else experiencing the same behavior?

thanks everyone for the help

Deploying Feature update to Windows 10 Enterprise, version 1607, en-us

$
0
0

I am using Microsoft System Center Configuration Manager Version 1606.  I am trying to deploy this update to a collection of Windows 10 machines.  I am getting the following error:

Deploying Feature update to Windows 10 Enterprise, version 1607, en-us

Receive Error Code 0x80091007  The hash value is not correct.


Problem with servicing of Windows 10 machines using SCCM

$
0
0

Hi all,

WaaS (Servicing plan )– we are facing issue at client machine windows 10 (1511) when we are deploying upgrade(1607) using SCCM 2012 and getting error :-

 

ERROR:

WSUS update (af57b397-b222-494e-ab73-17ddddd6e44e) installation result = 0xc1800118, Reboot State = NoReboot

Update execution failed.

Feature update to Windows 10 Enterprise version 1607 keeps failing on all client machines

$
0
0
Good day,
Has anyone perhaps had the same issue where the Feature update to Windows 10 version 1607 fails on the client machines.
 I have had some feedback from various Forums suggesting that we add .esd to the MIME TYPE
Infrastructure updated.
Is there perhaps something that we might have missed or any suggestions.

SCEP ADR failed to install updates with error description "success"

$
0
0

Hi,

On SCCM Current Branch 1606, i have a strange behavior with the report of an ADR for Endpoint Protection definitions.

I've set the logs to report only "error messages" on the deployment.

The ADR works  but i get errors with "success" reported as the error description. (error code 0x0000000)

Is this because of the "only report error messages" setting at the deployment?

PS: I would like to post a picture but my account need to be verified first.

Thanks,

David

Where is link for Offline installer, scepinstall.exe for latest version, curently 4.7.209 ???????

$
0
0

Where is link for Offline installer, scepinstall.exe for latest version, currently 4.7.209 ???????

I have looked for a link in the past for the scepinstall.exe file and it is always a MAJOR PAIN, if not impossible to find!!!!!!

Microsoft NO LONGER HAS AN EXCUSE FOR THIS LINK NOT EXISTING!!!!!!!!!

They have been told that it needs to exist and the logic for it is without error.

The ANSWER WILL NOT BE IT DOES NOT EXIST!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

There is NO EXCUSE FOR THIS NOT TO BE AN EASY TO FIND DOWNLOAD MICROSOFT, NO EXCUSE, except maybe laziness or greed, but no technical or legal reason for it not being made available, obviously!!!!!!!!!!!!!!!!!!!!!!!!!!

There MUST BE A PERMANENT LINK MAINTAINED BY MICROSOFT WHERE I CAN AT ALL TIMES GO TO DOWNLOAD THE LATEST GREATEST STANDALONE SCEP CLIENT AT ALL TIMES!!!!!!!

Today it would contain version 4.7.209. When the next version is release I will click on the same link and it will down load that new version EVERY TIME, NO EXCEPTIONS!!!!!!!!!!!!!!!

I have been able to capture, during an update the epplauncher.exe file and its accompanying folders etc, but that installer does not support any command line switches like the scepinstall.exe version for the client installer does. Needless to say that is ridiculous and stupid and incompetent of Microsoft to do, but that is what they did so needless to say I need the SCEPINSTAL.EXE version of the client installer that supports the command line switches, x64 and x86 in one file, no need to program in a check for that. And of course a link is absolutely required so that I can always find the latest version and I will never have to re-write my install script every time the install files changes, or a new version comes out, nor spend time trying to capture the file during an update etc. etc. etc.

Also don't tell me to go to the SCCM administrator, because he doesn't have a clue as to where this can be found or even that it exist. (The link given in the forums for finding it on the SCCM server DOES not maintain the latest greatest version at all times so that is also not the answer.)

I should also NEVER have to extract it from the SCCM updates such as "Cumulative Update 4 for ConfigMgr 2012 R2" which is where I found the 4.6.305 version a few months ago.

Thanks for the help, get your act in gear MS,

Ralph

Client not downloading Windows Updates.

$
0
0

Recently migrated Site server to 2012 R2 O/S and upgraded to 1511.  Now seeing that windows updates are being downloaded and showing up on the server console.  On the client side the clients have downloaded the updates to the ccmcache folder but for some reason they are not installing and the Software Center shows them preparing to download. 

Does anyone have any ideas what is causing this?

Some Clients Not Updating. Reporting "Compliant." hr=8007000E Error in WindowsUpdate.log

$
0
0

I have a significant number (but not all) of my SCCM 2012 R2 CU3 clients not updating though my SCCM software updates. On these problem clients, I get this error in WindowsUpdate.log:

"COMAPI WARNING: ISusInternal::GetUpdateMetadata2 failed, hr=8007000E"

Then these machines report "Compliant" even though they don't install the updates. Almost all of our workstations are Windows 7 SP1 32bit. We are running SCCM 2012 R2 CU3. My site servers are running Windows 2008 R2.

I don't see much in WUAhandler.log or scanagent.log. These client are however, getting my SCEP definition updates just fine. (I have an ADR for those.) And when you go out to Microsoft for security updates it works. I have tried all of the usual Windows Updates repair suggestions (re-register dlls, rename software distribution folder, etc.) And I tried un-installing and re-installing the SCCM client on a problem PC, to no avail. I also tried using a Software Update Group with fewer updates (<100) and targeting a problem system with only that SUG, to no avail.

Any assistance would be greatly appreciated. Thank you.

Pkgxfermgr.log "failed to get volume information of drive D:\"

$
0
0

I am seeing a continual "failed to get volume information of drive D: in my pkgxfermgr.log when updating my remote distribution points with my update packages. The drives are online and the maching is pingable. Any clue where this is coming from or what is causing this?

I have my DP's set to 15% when transferring data during specific times during the day and I see that in the log at the same time.  This is happening on multiple DP's while the transfer is going on.

Is this something to worry about or just normal logging in this file?


What is the daily average size of SCEP? Many clients dont show updated size on server

$
0
0

1,What is the average size of SCEP update?

2. I have SCCM 2012 R2 SP1 where hundreds of clients are updating regularly but their AV status and updated date are not reflecting on the SCCM Server.

updates don't appear on software center

$
0
0

Hi all,

I have an issue on my secondary sites clients, CIs for updates aren't downloaded and so they don't appear on software center and can't be installed. I found these errors on DataTransferService.log :

DTSJob {AFC32CC3-EDEC-489F-8E02-2D4F97DC6292} in state 'DownloadingData'. DataTransferService 31/10/2016 05:43:25 3348 (0x0D14)

CDTSJob::HandleErrors: DTS Job '{AFC32CC3-EDEC-489F-8E02-2D4F97DC6292}' BITS Job '{B10D33C2-FF52-452A-B2C7-783D437678F0}' under user 'S-1-5-18' OldErrorCount 0 NewErrorCount 1 ErrorCode 0x801901F4 DataTransferService 31/10/2016 05:43:25 3272 (0x0CC8)

CDTSJob::HandleErrors: DTS Job ID='{AFC32CC3-EDEC-489F-8E02-2D4F97DC6292}' URL='http://<my serevr fqdn>:80/SMS_MP' ProtType=1 DataTransferService 31/10/2016 05:43:25 3272 (0x0CC8)

Any idea on how to fix it?

How to get report of SCCM clients not patched for last 2 months

$
0
0

Hello Guys,

I am looking for a SSRS report which provide a list of computers not patched for last 60 days due to any reason. Report may include last patch date of each machine, no. of approved patches missing and last scan status. Please consider me novice in SCCM.

I am approving patches in SCCM by setting the custom severity field to "critical" and then running ADR using that condition which is creating a new Software update group every month.

Thanks..

Himanshu Rana


https://www.udemy.com/mastering-dns-on-windows-server-2012-r2/?couponCode=code100 MCTS|MCSE|MCSA:Messaging|CCNA

Endpoint Protection - Error 0x80070643

$
0
0

Hello,

I want to install Endpoint Protection through SCCM 2012, but it fails with the PCs that have had installed "microsoft security essentials". I have tried to install it uninstalling it before, without uninstalling it before... but nothing works. The error that appears on the SCCM 2012 console is:

[EppSetupResult]
HRESULT=0x80070645
Description=Cannot complete the System Center Endpoint Protection installation. An error has prevented the System Center Endpoint Protection setup wizard from completing successfully. Please restart your computer and try again. Error code:0x80070645. (null)

Thank you in advance.

SCCM 2012 SUP User Notification

$
0
0

Good Evening All - 

After presenting SCCM 2012's SUP feature to my manager, he wants me to implement it.  The only thing that he requested, though, is for a few changes (if possible) for user notification.

Through research and testing, I've found that when updates are advertised to a workstation, a system tray icons appears with a balloon.  If clicked on, there are a few options that the user has including viewing detail of the updates in the Software Center.  Example

Here are the changes my manager asked if I could make.  Any ideas on how this may be possible if it all?  

-  Instead of system tray icon notification, have a window pop up on their screen that must be dismissed

-  Possible to not use Software Center for updates (users don't need all of that detail as it would just confuse them)?  Actually, is there any way to not have Software Center install with the client on workstations altogether?

I think that's it - Thanks for your thoughts!


Ben K.

Viewing all 6382 articles
Browse latest View live