Quantcast
Channel: Configuration Manager 2012 - Security, Updates and Compliance forum
Viewing all 6382 articles
Browse latest View live

WSUS Database not creating on SQL server

$
0
0

Hi

I just setup my Microsoft SCCM lab. I installed SQL and Primary Site server on same server.

My Configuration manager installation done successfully. I done WSUS service installation in that i choosen SQL database but SUSDB not created on SQL Server.

Whats wrong here or Can i create manuall SUSDB on SQL Server but how to connect with Software update point


SCCM Software update "Suppress Reboot" make it mandatory

$
0
0

Hi,

is there any way to make the suppress reboot option checked always ?

when ever i make a deployment package, suppress reboot option is already checked.

Regards

SUP sync problem: Category products not found on WSUS

$
0
0

Hello,

Updates stopped working suddenly for clients, and the clients reported back with message: "Client check passed/Active".
I can't say much about it because I have to be honest, I didn't do much troubleshooting.

I went straight to re-configuration of SUP/WSUS.
So I removed the SUP CM role, and WSUS and re-installed everything again.
I did this several times now and followed similar procedures, but slightly different.

Basically:

Remove SUP
Remove WSUS
Restart
Install WSUS
Install the two famous updates
Restart
Add SUP role

Environment (one machine):
Server: 2008 R2
SCCM: 2012 SP1 - 5.0.7804.1000
WSUS 3.0 SP2 with both KB's

Syncing doesn't work.
From the wsyncmgr.log I'd say that SCCM is unable to communicate with WSUS.
From the wcm.log I'd think that Category Products are enabled on SCCM which cannot be found on WSUS, which I find a strange reason to block the whole Updating process but who am I to critisize. :-)
The problem is that I can't find these products in SCCM, let alone disable.

I really hope someone can help me out with this as this is starting to drive me crazy.
Also tried to run the WSUS configuration wizard partially until the products but that didn't help either.

Each time I restart the whole configuration, when I add the SUP role it seems to remember my settings. Is there a proper way to completely remove SUP?

WCM.log:

Category Product:70cfad70-6629-b54b-5819-c809a605515e (Adobe Flash Player) not found on WSUSSMS_WSUS_CONFIGURATION_MANAGER13/12/2013 15:32:125572 (0x15C4)
Category Product:e1d507be-497c-d8fd-61d7-b0d93ee399ca (Adobe Reader) not found on WSUSSMS_WSUS_CONFIGURATION_MANAGER13/12/2013 15:32:125572 (0x15C4)
Subscription contains categories unknown to WSUS. SMS_WSUS_CONFIGURATION_MANAGER13/12/2013 15:32:125572 (0x15C4)
Failed to set Subscriptions on the WSUS Server. Error:(-2147467259)Unspecified errorSMS_WSUS_CONFIGURATION_MANAGER13/12/2013 15:32:125572 (0x15C4)

WSYNCMGR.log

Sync failed: WSUS server not configured. Please refer to WCM.log for configuration error details.. Source: CWSyncMgr::DoSyncSMS_WSUS_SYNC_MANAGER13/12/2013 15:37:125660 (0x161C)
STATMSG: ID=6703 SEV=E LEV=M SOURCE="SMS Server" COMP="SMS_WSUS_SYNC_MANAGER" SYS=SVCMSS001.mobilebelgium.be SITE=PS1 PID=5216 TID=5660 GMTDATE=Fri Dec 13 14:37:12.547 2013 ISTR0="CWSyncMgr::DoSync" ISTR1="WSUS server not configured. Please refer to WCM.log for configuration error details." ISTR2="" ISTR3="" ISTR4="" ISTR5="" ISTR6="" ISTR7="" ISTR8="" ISTR9="" NUMATTRS=0SMS_WSUS_SYNC_MANAGER13/12/2013 15:37:125660 (0x161C)
Sync failed. Will retry in 60 minutesSMS_WSUS_SYNC_MANAGER13/12/2013 15:37:125660 (0x161C)

WindowsUpdateFailure

$
0
0

Dear all,

I have SCCM 2012 R2 SP1 and i have a problem with windows updates. So i sent updates to about 150 windows 7 pc's. The updates are installed succesfully to about 112 PC's, the rest have the following errors

-Fault bucket 3031265172, type 5
Event Name: WindowsUpdateFailure

-Fault bucket , type 0
Event Name: WindowsUpdateFailure

Could someone help?

Regards

pantos

Patch scan report for all the client machines

$
0
0

Hi,

I am new to SCCM. We have SCCM 2012 in our customer environment. Management wants me to get a patch scan report for all the servers added in a collection. Report should have the information like, installed patches, last installed on date, missing patches, pending status etc. I am really not sure how to get this as I don't see any options under the SCCM monitoring->reports. Please let me know if there is any way to get this kind of report using SCCM console or is there any script available to do this.

Thanks,

Umesh.S.K

Configuring DMZ with Internal Distribution Point for Internet Based Client Management Services

$
0
0

I am working with a Infrastructure Group on trying to configure a Distribution Point on the DMZ Server.  This Distribution Point will need be configured on DMZ Server as Workgroup and not on no domain.  That eventual DMZ Distribution Point will communicate to an internal SCCM Distribution Point within a private network and communicate to Windows Clients on the internet for Security Updates with Software Update Point.  Is there any engineers in the past that had this type of experience doing these type of configurations.   If so, What would be the recommendation for doing this type of setup?

Software Update ADR's WINHTTP proxy & pac file

$
0
0

Hi All,

Couple of questions if anyone can advise:

We need to use a pac file for proxy access on our primary site with SUP role, can this be set as a pac file?

Do ADR's use WINHTTP proxy if no account is set for SUP proxy account?

Thanks in advance

Computers that have run a specific metered software program not listing Month and year value

$
0
0

I just configured software metering but unable to populate Month and year value in "Computers that have run a specific metered software program" Reports..


Hard disk size and free size results in SCCM SQL report

Client Check passed / Active and Inactive Computers.

$
0
0
I need an trouble shooting document  for clients showing in unknown status as Client check passed/Inactive and inactive as well client check failed / Active this causing problem for my compliance. All the computers are in remote due to WFH for the Covid 19. this affecting my compliance report.

I need to create a Collection of machines missing for a single patch

$
0
0
I need to create a Collection of machines missing for a single patch by using ComplianceStatus Id where I can get the ID value of  "SMS_UpdateComplianceStatus.CI_ID "

SCCM 2016 Console and Compilance report Showing data different

$
0
0

Hi,

We have deployed SCCM 2016 in our environment and through SCCM we have push the windows updates but the problem is Some systems are showing compliant in SCCM Console but when checking the status of same machine in SCCM report its showing Non-Compliant and i don't know what is the problem.need expert opinion/solution.

Thanks

[RESOLVED] SCCM Current Branch 1906 - Compliance Report for Application and Windows Updates

$
0
0

Specs: 

SCCM Current Branch 1906

Windows 2016 x64 Enterprise - Build 1607

Microsoft SQL 2016 Standard

Symptoms:

About 2 weeks ago, around Nov 12th 2019 endpoints and server have stopped reporting their compliance.

Essentially, I can deploy patches and software to systems just fine and they install.

However when I check on the monitoring side via SCCM the packages do not get updated with compliant, in progress and whatnot, I'm completely blind as to what's going on.

Network side, I've verified via our SiEM verified of there's any traffic and none of the network firewalls are blocking and neither are endpoints and server blocking the traffic.

I check on the server and I don't really see any major errors...

I'm kind of dumbfounded at the moment as to what could be the cause... my reports are just not updating.

Also, as a result, let's say I build a compliance baseline config and deploy it to a collection and then build a collection based on the said compliance, no systems are appearing in the list...

Also for testing purposes, I clone one of my application package and re-deployed it and I'm not getting any status report even though I'm able to install and remove the package on the system target.

Please advise...



SCCM failed to sync with WSUS server

$
0
0

Dear all, 

im experiencing this issue and the WCM logs are displaying this error message. 

Failed to create assembly name object for Microsoft.UpdateServices.Administration. Error = 0x80131701 SMS_WSUS_CONFIGURATION_MANAGER5/14/2020 12:16:39 PM4196 (0x1064)
Supported WSUS version not foundSMS_WSUS_CONFIGURATION_MANAGER5/14/2020 12:16:39 PM4196 (0x1064)
Remote configuration failed on WSUS Server. SMS_WSUS_CONFIGURATION_MANAGER5/14/2020 12:16:39 PM4196 (0x1064)

and the WSYNC logs are displaying this error 

Sync failed: WSUS update source not found on site SCC. Please refer to WCM.log for configuration error details.. Source: getSiteUpdateSourceSMS_WSUS_SYNC_MANAGER5/14/2020 12:12:13 PM160 (0x00A0)

The WSUS is functioning, it is able to look for patches and updates. So i believe the problem lies on the SCCM server. I have done the configuration for the SUP and running a proxy,  The connection port is 8530.  

Can any kind souls can enlighten me to resolve this problem?

PCs not rebooting after Patching

$
0
0

Hello All,

SCCM 2012 SP1 R2 (upgrade to CB/Win10 will begin after 2 months)

Win 7 SP1 Pro


A few PCs (5%) are not rebooting post patching

The deployment status is "Pending Restart"

The scan status is 'Completed with Errors '-2145116137' (The OS servicing stack must be updated before this update is downloaded or installed)

This was our first Patching Cycle post Win7-EOL for Mar-2020 patches.

After ESU patch installed+rebooted, we Activated the MAK, then deployed the SSU which sometimes does not require a reboot. March SUG which includes the Rollup and other updates is scheduled a few hours from the SSU

Most PCs patched and rebooted successfully (90%), but 5% are not rebooting.Patches are installed successfully on them, but the reboot does not trigger

No MW is set from SCCM side. Not sure if users have it configured. Regardless, this is a mandatory deployment with 24 hour notification. We have waited 2 weeks now

Could someone suggest what is stopping these 5% PCs from rebooting, and what I can do to initiate it? Thanks.

Logs (Filtered):

---------------

WUAHandler:

---------------

Received 'SucceededWithErrors' code from WUA during search. Check WindowsUpdate.log in Windows directory.                WUAHandler     5/14/2020 8:30:41 PM    12508 (0x30DC)

WU Agent reported the following 2 warning messages: WUAHandler     5/14/2020 8:30:41 PM    12508 (0x30DC)

    HResult: 0x80242017 Context: uecGeneral Msg: (null).               WUAHandler     5/14/2020 8:30:41 PM    12508 (0x30DC)

    HResult: 0x00240005 Context: uecGeneral Msg: The computer needs to be rebooted to complete past installation. The result of search may be incorrect..           WUAHandler     5/14/2020 8:30:41 PM    12508 (0x30DC)

---------------

WindowsUpdate:

---------------

2020-05-14          20:22:03:553       1244       39a4       Agent    WARNING: failed to calculate prior restore point time with error 0x80070002; setting restore point

2020-05-14          20:22:45:502       5028       4bdc      Handler                Requesting post-reboot reporting for package Package_for_KB4550738~31bf3856ad364e35~amd64~~6.1.1.1.

2020-05-14          20:22:45:502       5028       4bdc      Handler                Completed install of CBS update with type=3, requiresReboot=1, installerError=0, hr=0x0

2020-05-14          20:23:53:004       1244       481c       Handler                FATAL: UH: 0x800f0823: CreatePackage failed in CCbs::CreatePackage

2020-05-14          20:23:53:004       1244       481c       Agent    WARNING: Failed to evaluate Installed rule, updateId = {9DBF4729-DC9B-484F-8638-A426CD922D42}.200, hr = 80242017

2020-05-14          20:30:41:492       6536       30dc       COMAPI                - Updates found = 267

2020-05-14          20:30:41:492       6536       30dc       COMAPI                - Reboot required

---------------

RebootCoordinator.log

----------------------

Entered ScheduleRebootImpl - requested from 'UpdatesDeploymentAgent'. set Rebootby = 1589506103. set NotifyUI = True. set PreferredRebootWindowType = 4        RebootCoordinator         5/14/2020 8:28:23 PM    16236 (0x3F6C)

An earlier reboot was already scheduled, only taken into account new parameters          RebootCoordinator         5/14/2020 8:28:23 PM          16236 (0x3F6C)

Reboot Coordinator received a SERVICEWINDOWEVENT START Event     RebootCoordinator         5/14/2020 10:00:00 PM  6732 (0x1A4C)

No CCM Identification blob         RebootCoordinator         5/14/2020 10:00:00 PM  6732 (0x1A4C)

Not in Maintenance/Service Mode, check ServiceWindowsManager next            RebootCoordinator         5/14/2020 10:00:00 PM         6732 (0x1A4C)

ServiceWindowsManager has not allowed us to Reboot                RebootCoordinator         5/14/2020 10:00:00 PM  6732 (0x1A4C)

---------------

ServiceWindowManager.log

--------------------

OnIsServiceWindowAvailable called with: Runtime:7200, Type:2                ServiceWindowManager              5/14/2020 8:28:12 PM         16236 (0x3F6C)

No Service Windows exist for this type. Will check if the program can run in the All Programs window...                ServiceWindowManager              5/14/2020 8:28:12 PM    16236 (0x3F6C)

        Biggest Active Service Window for Type=1 not found              ServiceWindowManager              5/14/2020 8:28:12 PM                16236 (0x3F6C)

Program cannot Run! Setting *canProgramRun to FALSE               ServiceWindowManager              5/14/2020 8:28:12 PM                16236 (0x3F6C)

WillProgramRun called with: Runtime:7200, Type:2          ServiceWindowManager              5/14/2020 8:28:12 PM    16236 (0x3F6C)

No Service Windows of this type exist.  ServiceWindowManager              5/14/2020 8:28:12 PM    16236 (0x3F6C)

There exists an All Programs window for this duration. The Program will run eventually.                ServiceWindowManager                5/14/2020 8:28:12 PM    16236 (0x3F6C)

OnIsServiceWindowAvailable called with: Runtime:1, Type:4       ServiceWindowManager              5/14/2020 10:00:00 PM                11596 (0x2D4C)

No Service Windows exist for this type. Will check if the program can run in the All Programs window...                ServiceWindowManager              5/14/2020 10:00:00 PM  11596 (0x2D4C)

        Biggest Active Service Window for Type=1 not found              ServiceWindowManager              5/14/2020 10:00:00 PM                11596 (0x2D4C)

Program cannot Run! Setting *canProgramRun to FALSE               ServiceWindowManager              5/14/2020 10:00:00 PM                11596 (0x2D4C)

WillProgramRun called with: Runtime:1, Type:4 ServiceWindowManager              5/14/2020 10:00:00 PM  11596 (0x2D4C)

No Service Windows of this type exist.  ServiceWindowManager              5/14/2020 10:00:00 PM  11596 (0x2D4C)

There exists an All Programs window for this duration. The Program will run eventually.                ServiceWindowManager                5/14/2020 10:00:00 PM  11596 (0x2D4C)

---------------

UpdatesDeployment.log

------------------------

No current service window available to run updates assignment with time required = 1 UpdatesDeploymentAgent                5/14/2020 10:00:00 PM  11596 (0x2D4C)

Suspend activity in presentation mode is selected            UpdatesDeploymentAgent         5/14/2020 10:00:00 PM  11596 (0x2D4C)

At least one user has elected to suspend non-business hours activity when in presentation mode. Checking for presentation mode.       UpdatesDeploymentAgent         5/14/2020 10:00:00 PM  11596 (0x2D4C)

Proceeding to non-business hours activites as presentation mode is off.               UpdatesDeploymentAgent         5/14/2020 10:00:00 PM       11596 (0x2D4C)

Auto install during non-business hours is disabled or never set, selecting only scheduled updates.                UpdatesDeploymentAgent         5/14/2020 10:00:00 PM  11596 (0x2D4C)

A user-defined service window(non-business hours) is available. We will attempt to install any scheduled updates.                UpdatesDeploymentAgent         5/14/2020 10:00:00 PM  11596 (0x2D4C)

Attempting to install 0 updates  UpdatesDeploymentAgent         5/14/2020 10:00:00 PM  11596 (0x2D4C)

No actionable updates for install task. No attempt required.       UpdatesDeploymentAgent         5/14/2020 10:00:00 PM                11596 (0x2D4C)

Updates could not be installed at this time. Waiting for the next maintenance window. UpdatesDeploymentAgent                5/14/2020 10:00:00 PM  11596 (0x2D4C)

--------------

Scan Agent

--------------

- - -Evaluating Update Status...  ScanAgent          5/14/2020 8:30:48 PM    12596 (0x3134)

ScanJob({5537ACFF-E72C-4AEF-B0E2-4D8983A1A323}): Scan Succeeded, setting flag that performed scan was catscan                ScanAgent          5/14/2020 8:30:48 PM    18544 (0x4870)

ScanJob({5537ACFF-E72C-4AEF-B0E2-4D8983A1A323}): CScanJob::OnScanComplete - Scan completed successfully, ScanType=2        ScanAgent          5/14/2020 8:30:48 PM    18544 (0x4870)

ScanJob({5537ACFF-E72C-4AEF-B0E2-4D8983A1A323}): CScanJobManager::OnScanComplete -ScanJob is completed.                ScanAgent          5/14/2020 8:30:48 PM    18544 (0x4870)

ScanJob({5537ACFF-E72C-4AEF-B0E2-4D8983A1A323}): CScanJobManager::OnScanComplete - Reporting Scan request complete to clients...     ScanAgent          5/14/2020 8:30:48 PM    18544 (0x4870)

- - -Evaluating Update Status...  ScanAgent          5/14/2020 8:30:48 PM    18544 (0x4870)

- - Calling back to client on Scan request complete...        ScanAgent          5/14/2020 8:30:49 PM    18416 (0x47F0)

- - Calling back to client on Scan request complete...        ScanAgent          5/14/2020 8:30:49 PM    8044 (0x1F6C)


Endpoint protection definition update deployment

$
0
0

Hello,

I have created a ADR for downloading definition updates, The ADR is working fine and downloading and deploying the updates but the client machines are not installing the updates....The machines are windows 10 machines which are constantly online and syncing with SCCM but they are not downloading the definition updates. How can I troubleshoot this.

Thanks!

Pranay.

MECM Managed Windows Defender ignoring policy settings and user interface question.

$
0
0

We are experiencing odd behavior with scheduled scans ignoring CPU limits.

I configured the policy to allow users full control of settings, scan times, CPU usage, etc but do not see those options on the PCs.

I know the client interface changed when it started using the native Defender but it seems like it should honor the policy settings.

What am I missing here?

Thanks


SCCM - software updates - Not required.

$
0
0

Hi All,

Can some one help with the understanding of "Not Required" software updates. How does actually SCCM decides why a particular software update is not required for a machine.

Rgs,

Can 1803 & 1909 Enterprise clients coexist in SCCM 2012 ?

$
0
0
Current SOE is W10 Enterprise 1803 managed and updates patched via SCCM 2012 R2. We are purchasing new devices with W10 Enterprise 1909. We need both SOE's (1803 & 1909) to coexist while we replace 1803 devices in stages. Can the 1909 devices be added to SCCM and get ADR Microsoft Monthly Updates  without interfering with our existing 1803 client updates ? We do not want the 1803 devices to update their OS to 1909 version. Can 1809 & 1909 devices coexist and have trouble free monthly security patching via SCCM ADR's ? Thanks for advice.

NC

Microsoft Windows Server Patches not installing on 2008 R2 Standard (SP1).

$
0
0

Hi Team,

1) While installing patches manually on 2008 R2 servers Getting message as 

"The Windows Modules Installer must be updated before you can install this package. 
Please update the windows modules installer on your computer , then retry setup. "

Even viewer error: 

The Windows Modules Installer must be updated before you can install this package (Command line: ""C:\Windows\system32\wusa.exe" "C:\temp\win 2008R2\win 2008R2\windows6.1-kb4550905-x64_ec45614587de8c5caeeaddce84ab2d1b0ac918d7.msu"       ")

2) We have downloaded MSU instaler from below MS link and try to install the KB2533552 on server but it's not installing 

Getting message as " The update is not applicable to your computer"


URL:  https://support.microsoft.com/en-us/help/925316/error-message-when-you-install-a-msu-update-package-on-a-computer-that

Is Microsoft supporting 2008 R2 OS?
if not, why we have 2008 R2 patches available for these servers. 
How can we fix this patches not installing on 2008 R2 servers?

Could you please help me on this issue?

Thanks in Advance!


Thanks & Regards, Balaji G (from microsoft alert forum)

Viewing all 6382 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>