Quantcast
Channel: Configuration Manager 2012 - Security, Updates and Compliance forum
Viewing all 6382 articles
Browse latest View live

KB4039929 it will supports windows 10 patching

$
0
0

I have SCCM server 2012 R2 SP1 , Windows server operating system 2008 R2, WSUS server 3.2.7600.279 installed KB 298066 if i install another KB4039929 it will supports windows 10 patching?

Right now  Windows 10 machine scanning throws error 0x8024401c , updatedeployment , scansgent, windows update, WUA hanndler throws same error

ports  are open and client able to ping WSUS or SCCM server



SUP sync problem: Category products not found on WSUS

$
0
0

Hello,

Updates stopped working suddenly for clients, and the clients reported back with message: "Client check passed/Active".
I can't say much about it because I have to be honest, I didn't do much troubleshooting.

I went straight to re-configuration of SUP/WSUS.
So I removed the SUP CM role, and WSUS and re-installed everything again.
I did this several times now and followed similar procedures, but slightly different.

Basically:

Remove SUP
Remove WSUS
Restart
Install WSUS
Install the two famous updates
Restart
Add SUP role

Environment (one machine):
Server: 2008 R2
SCCM: 2012 SP1 - 5.0.7804.1000
WSUS 3.0 SP2 with both KB's

Syncing doesn't work.
From the wsyncmgr.log I'd say that SCCM is unable to communicate with WSUS.
From the wcm.log I'd think that Category Products are enabled on SCCM which cannot be found on WSUS, which I find a strange reason to block the whole Updating process but who am I to critisize. :-)
The problem is that I can't find these products in SCCM, let alone disable.

I really hope someone can help me out with this as this is starting to drive me crazy.
Also tried to run the WSUS configuration wizard partially until the products but that didn't help either.

Each time I restart the whole configuration, when I add the SUP role it seems to remember my settings. Is there a proper way to completely remove SUP?

WCM.log:

Category Product:70cfad70-6629-b54b-5819-c809a605515e (Adobe Flash Player) not found on WSUSSMS_WSUS_CONFIGURATION_MANAGER13/12/2013 15:32:125572 (0x15C4)
Category Product:e1d507be-497c-d8fd-61d7-b0d93ee399ca (Adobe Reader) not found on WSUSSMS_WSUS_CONFIGURATION_MANAGER13/12/2013 15:32:125572 (0x15C4)
Subscription contains categories unknown to WSUS. SMS_WSUS_CONFIGURATION_MANAGER13/12/2013 15:32:125572 (0x15C4)
Failed to set Subscriptions on the WSUS Server. Error:(-2147467259)Unspecified errorSMS_WSUS_CONFIGURATION_MANAGER13/12/2013 15:32:125572 (0x15C4)

WSYNCMGR.log

Sync failed: WSUS server not configured. Please refer to WCM.log for configuration error details.. Source: CWSyncMgr::DoSyncSMS_WSUS_SYNC_MANAGER13/12/2013 15:37:125660 (0x161C)
STATMSG: ID=6703 SEV=E LEV=M SOURCE="SMS Server" COMP="SMS_WSUS_SYNC_MANAGER" SYS=SVCMSS001.mobilebelgium.be SITE=PS1 PID=5216 TID=5660 GMTDATE=Fri Dec 13 14:37:12.547 2013 ISTR0="CWSyncMgr::DoSync" ISTR1="WSUS server not configured. Please refer to WCM.log for configuration error details." ISTR2="" ISTR3="" ISTR4="" ISTR5="" ISTR6="" ISTR7="" ISTR8="" ISTR9="" NUMATTRS=0SMS_WSUS_SYNC_MANAGER13/12/2013 15:37:125660 (0x161C)
Sync failed. Will retry in 60 minutesSMS_WSUS_SYNC_MANAGER13/12/2013 15:37:125660 (0x161C)

Keep getting SUP sync errors

$
0
0

Here is what the wsynmgr.log shows:

Sync failed: Execution Timeout Expired.  The timeout period elapsed prior to completion of the operation or the server is not responding. Source:Microsoft.UpdateServices.Internal.BaseApi.SoapExceptionProcessor.DeserializeAndThrowSMS_WSUS_SYNC_MANAGER10/9/2018 10:26:10 PM13284 (0x33E4)
STATMSG: ID=6703 SEV=E LEV=M SOURCE="SMS Server" COMP="SMS_WSUS_SYNC_MANAGER" SYS=MY-SCCM-SERVER.MY.DOMAIN.COM SITE=PR1 PID=12796 TID=13284 GMTDATE=Wed Oct 10 05:26:10.445 2018 ISTR0="Microsoft.UpdateServices.Internal.BaseApi.SoapExceptionProcessor.DeserializeAndThrow" ISTR1="Execution Timeout Expired.  The timeout period elapsed prior to completion of the operation or the server is not responding" ISTR2="" ISTR3="" ISTR4="" ISTR5="" ISTR6="" ISTR7="" ISTR8="" ISTR9="" NUMATTRS=0SMS_WSUS_SYNC_MANAGER10/9/2018 10:26:10 PM13284 (0x33E4)
Sync failed. Will retry in 60 minutesSMS_WSUS_SYNC_MANAGER10/9/2018 10:26:10 PM13284 (0x33E4)

I did the following to try and resolve this:

  • Unchecked all classifications
  • Ran sync again

But, it keeps getting these errors. 

Thanks


Pkgxfermgr.log "failed to get volume information of drive D:\"

$
0
0

I am seeing a continual "failed to get volume information of drive D: in my pkgxfermgr.log when updating my remote distribution points with my update packages. The drives are online and the maching is pingable. Any clue where this is coming from or what is causing this?

I have my DP's set to 15% when transferring data during specific times during the day and I see that in the log at the same time.  This is happening on multiple DP's while the transfer is going on.

Is this something to worry about or just normal logging in this file?

Why "some" Windows Update do not show in my SCCM All Software Updates?

$
0
0

Hi

I am running SCCM 1710. I have "Updates Classification" category selected to be synchronized and I see some Updates listed.  

However, for example KB4457136 and KB4457127 are September 2018 replacements to KB4457131 and 4464217 Cumulative Updates respectively but they (KB4457136 and 4457127) do not appear in my "All Software Updates".  I do see Cumulative for October 2018 and other updates such as 4464217.

My question is, how come these updates "in between" the major monthly cumulative updates such as KB4457136 and KB4457127 do not appear in my Software Updates list while other updates in the "Updates Classification" show up (ex. 4464217).

Anyone know? Thank you!


 

Force SCEP policy on clients

$
0
0

Goodmorning.

I have just deployed a SCEP policy to a collection to update some antimalware folder exclusions.

I cannot figure out if is there a way to force all the clients in the collection to update their policy immediately, or all I can do is sit-and-wait for the policy to be retrieved from the SCCM client.

How can I check if the policy has been applied to all clients in the collection?

Thank you for your kind help

update failed xml core KB954430 and KB973688

$
0
0

Hi

We're deploying patches for Windows 7

The below updated is failed to install

1. KB954430

2. KB973688

Please advise  and what is the solution ?


Help.Me

Software Updates Error Code 0x8000FFF Catastrophic Failure

$
0
0

Has anyone else seen this before? As you can see in the graph, there are a significant number of errors, and almost of those errors are showing 0x8000FFF Catastrophic Failure (with the majority of the remaining errors showing Success!! :D great work SUP stats....).

The reason I am posting here is that there is literally nothing else on the internet about this error code in relation to SCCM.

Any ideas what Catastrophic Failure actually means? When i check the local logs of individual machines, i am seeing some with the updates installed, some with some updates installed - None are showing any error codes or messages relating to the above, so this doesn't make sense.

PS While you are at it - Why are successes showing in the Error section?? I see those every month.......


wsus database error

$
0
0

Sccm 2012 r2 sp1 doing wsus clean up steps

Open wsus console-- options--server cleanup-- selected unused updates and update revisions

Throwing wsus console error database error

Server 2008 r2

Wsus 3.0 sp2 3.2.7600

Updates Sync failure in SCCM 2012

$
0
0

HI All,

We are facing issue with update Sync, in CAS of sccm 2012, and when I checked WSYNCMGR log file in CAS, I found below error can any one help with this please.

ERROR: Still waiting for SMS_INBOX_MANAGER to create the "Site Control Manager (Master Site Control File)" inbox.  Sleeping for 60 seconds.  The operating system reported error 5: Access is denied.

Thanks in advance


Vinod Kumar Devaragatla

Help with Software Update Point Component Products

$
0
0

When selecting products for Windows 10 Version 1607 (Anniversary) which products do I select to receive just updates for this version?

Do I need just:

Windows 10 Anniversiary Update and Later Servicing Drivers

Windows 10 Anniversary Update and Later upgrade & Servicing Drivers

or do I need the above 2 and:

Windows 10

Windows 10 and later drivers?

Thanks for your help!

Wsyncmgr.log : The Microsoft Software License Terms have not been completely downloaded and~~cannot be accepted

$
0
0

Hi,

I manage an SUP SCCM CB server.

For the same synchronization run, while the WSUS synchronization completes, Configuration Manager return an 0X80131500 error code.

Wsyncmgr.log keep displaying the error below :

sync: SMS synchronizing updates, processed 2872 out of 2872 items (100%)    SMS_WSUS_SYNC_MANAGER17/10/2018 12:18:19              7236 (0x1C44)

Sync failures summary:               SMS_WSUS_SYNC_MANAGER17/10/2018 11:29:34      5540 (0x15A4)

Failed to sync update 0c1a2ac7-9f11-44ec-a959-58e29ecd7a61. Error: The Microsoft Software License Terms have not been completely downloaded and~~cannot be accepted. Source: Microsoft.UpdateServices.Internal.BaseApi.LicenseAgreement.GetById          SMS_WSUS_SYNC_MANAGER17/10/2018 11:29:34              5540 (0x15A4)

Failed to sync update 159d5d3e-6114-4940-b3da-406e46dca8a1. Error: The Microsoft Software License Terms have not been completely downloaded and~~cannot be accepted. Source: Microsoft.UpdateServices.Internal.BaseApi.LicenseAgreement.GetById          SMS_WSUS_SYNC_MANAGER17/10/2018 11:29:34              5540 (0x15A4)

Sync failed: Failed to sync some of the updates. Source: Microsoft.SystemsManagementServer.SoftwareUpdatesManagement.WsusSyncAction.WSyncAction.SyncUpdates               SMS_WSUS_SYNC_MANAGER17/10/2018 11:29:34      8796 (0x225C)

STATMSG: ID=6703 SEV=E LEV=M SOURCE="SMS Server" COMP="SMS_WSUS_SYNC_MANAGER" SYS=ABCD.1234=AES PID=2592 TID=8796 GMTDATE=mer. oct. 17 09:29:34.779 2018 ISTR0="Microsoft.SystemsManagementServer.SoftwareUpdatesManagement.WsusSyncAction.WSyncAction.SyncUpdates" ISTR1="Failed to sync some of the updates" ISTR2="" ISTR3="" ISTR4="" ISTR5="" ISTR6="" ISTR7="" ISTR8="" ISTR9="" NUMATTRS=0  SMS_WSUS_SYNC_MANAGER17/10/2018 11:29:34      8796 (0x225C)

Sync failed. Will retry in 60 minutes       SMS_WSUS_SYNC_MANAGER17/10/2018 11:29:34      8796 (0x225C)

This issue seems to concern Configuration Manager services and not WSUS ones...

Please share your thought,

Best regards,

PCJ_TECH

Can't install upgrade Windows 10 1703 (error 0xc1800118)

$
0
0

Hellow All. 

When we try to deploy upgrade Windows 10 1703 via service plan SCCM (1806), we have error 0xc1800118".

"Picture" very look like on

https://support.microsoft.com/en-sg/help/3194588/0xc1800118-error-when-you-push-windows-10-version-1607-by-using-wsus

setuperr.log and setupact.log have yge same issuses.

After using "workaround" problem wasn't solved.

When we use request 

select TotalResults = Count(*)
from tbFile
where (FileName like '%15063%.esd' and IsEncrypted = 0)

it's show 20 results,

when

select Count(*)
from tbFile as f, tbFileForRevision as fr, tbRevision as r, tbUpdate as u, tbProperty as p
where f.FileDigest = fr.FileDigest and fr.RevisionID = r.RevisionID and r.LocalUpdateID = u.LocalUpdateID
and p.RevisionID = r.RevisionID and 
(f.FileName like '%15063%.esd' or f.FileName like '%14393%.esd' or f.IsEncrypted = 1) 
and f.DecryptionKey is null
and p.PublicationState = 0

it's show 10.

After request

select * from tbFile where FileName like '%15063%.esd'

We see upgrades without key.

KB3095113 and KB3159706 was installed.

But updates wasn't applicable and we used procedure from this article 

https://sccmnotes.wordpress.com/2018/02/12/kb3159706-the-update-is-not-applicable-to-your-computer/.

But when we trying start postinstall  "C:\Program Files\Update Services\Tools\wsusutil.exe postinstall /servicing", we have error :

Fatal Error: Could not find a part of the path 'C:\Program Files\Update Services
\Database\VersionCheck.sql'.

In server manager WSUS WID wasn't install.

Windows 10 servicing update not showing

$
0
0

Hi,
When using Windows 10 servicing some computesr doesn't show 1803 featured update in Software Center.
Common point : These computer where upgraded from Windows 7 to Windows 10 via SCCM (Task Sequence Migration) but they show as compliant in the deployment..

Thanks 

Failed to evaluate Installable rule, hr = 8007006E

$
0
0

Hi All,

Some of my machines are showing below error in windowsupdate.loog file and in compliance report the machine is missing some updates also.

I have tried to search this UpdateIDs in v_UpdateInfo table and not able to find any of them.

2018-01-2816:23:35:5154881b80AgentWARNING: Failed to evaluate Installable rule, updateId = {297C81E7-D5A1-4C5A-B7A4-9BB021409ED1}.201, hr = 8007006E
2018-01-2816:23:35:8744881b80AgentWARNING: Failed to evaluate Installable rule, updateId = {E30A4DF5-A217-4740-86EB-6A033DC018F8}.200, hr = 8007006E
2018-01-2816:23:41:1944881b80AgentWARNING: Failed to evaluate Installable rule, updateId = {38D9083C-B4D8-4A7A-89B4-8A4874479023}.200, hr = 8007006E
2018-01-2816:23:41:2564881b80AgentWARNING: Failed to evaluate Installable rule, updateId = {5A529FAA-D58B-404D-83DF-82D74EFA671E}.200, hr = 8007006E
2018-01-2816:23:41:2874881b80AgentWARNING: Failed to evaluate Installable rule, updateId = {8B28AAAF-4732-4E6B-ABB6-6BF5B6B63C63}.201, hr = 8007006E
2018-01-2816:23:43:3154881b80AgentWARNING: Failed to evaluate Installable rule, updateId = {2C4EBD9F-0ED9-45E0-B935-CACEB0415240}.200, hr = 8007006E
2018-01-2816:23:44:5164881b80AgentWARNING: Failed to evaluate Installable rule, updateId = {75101677-72C9-453A-97E5-C6EED83892AC}.200, hr = 8007006E
2018-01-2816:23:44:7824881b80AgentWARNING: Failed to evaluate Installable rule, updateId = {D017E66F-4E1C-40DE-979E-32498077017D}.201, hr = 8007006E
2018-01-2816:23:46:0304881b80AgentWARNING: Failed to evaluate Installable rule, updateId = {E145283C-A6DE-4877-A611-6F5F3E6DBF91}.200, hr = 8007006E
2018-01-2816:23:46:3424881b80AgentWARNING: Failed to evaluate Installable rule, updateId = {AB7D0BB4-F32D-4B91-A498-3853A4058EDE}.200, hr = 8007006E
2018-01-2816:23:47:3874881b80AgentWARNING: Failed to evaluate Installable rule, updateId = {0B3640B7-3457-4417-801F-EDAFFB4D871B}.201, hr = 8007006E
2018-01-2816:23:47:6214881b80AgentWARNING: Failed to evaluate Installable rule, updateId = {088EFC5F-FFF9-4041-880F-EEFFCCB7A288}.201, hr = 8007006E

Anything I can do to troubleshoot the issue ?


SCCM 2012 Installation "Super Administrator" Account deleted

$
0
0

Hello,

I was asked to take over a SCCM 2012 environment. I was getting a lot of "Could not connect to the "REGISTRY" inbox source on computer 5.  Sleeping for 60 seconds.  The operating system reported error 53: The network path was not found."

what I found was SCCM 2012 Installation "Super Administrator" Account was deleted.  Is there procedure to elevate my current sccm administrator account to the level of the deleted Installation account with Super Admin rights?

Thanks,

Mark

Update not showing up in SCCM but are in WSUS and not suerseded

$
0
0

Hi All,

I'm having an issue and can't seem to figure out why its happening. It seems there's an update, KB 4103723, that isn't showing up in SCCM's "All Software Updates" but is in WSUS. It doesn't appear to be superseded, and I've confirm in SCCM, that I'm covering the classification and Product. Clasification: Security Updates and Product: Windows 2016. So I'm not sure why it isn't being captured by SCCM. I'm getting other updates fine that i know of. Any help would be appreciated.

SCEP vs McAfee

$
0
0

We are using MS System Center Configuration Manager 2012 R2. We are planning to replace McAfee with System Center End Point Protection.

Furthermore, following McAfee software features / add-on are being used in our environment;

AV for Servers and Workstations

Spyware

DLP for USB blocking

Move for virtualized environment

NAS scanning (CAVA)

ICAP for Isilon Scanning

Exchange server scanner

Integration of end point security solution with Microsoft NAP is required to monitor and ensure latest definition file on clients.

Our present Mcafee setup has central management server and master repository which pulls dat file from web and copy it to distributed repositories located on remote branches. This existing solution also provides capability to manage outbreaks and rollback definition file in case any malfunction.

Please suggest and share your experience in this regards.


Regards, Syed Fahad Ali

How to get Operating System and IP address of Windows Servers and Workstation in SCCM?

$
0
0

Hi, Guys.

How to get Operating Systems and IP address of Windows Servers and Workstations in SCCM? Thank you

Content download failed. Message: Failed to download one or more content files. Source: SMS Rule Engine.

$
0
0

Having issues getting Automatic deployment rule to run for Endpoint. It ran the first time I created it and ran the next scheduled time, but every time after that it fails with the above message in status message viewer. when I go to the ruleengine.log it states in the pic below. I can setup manual update packages / software update groups and can download and deploy definitions, but as soon as I use a ADR I get these errors. I have seen the error=5 in other posts which is permissions issues, but I get error=193...??

 
Viewing all 6382 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>