Quantcast
Channel: Configuration Manager 2012 - Security, Updates and Compliance forum
Viewing all 6382 articles
Browse latest View live

WSUS to Remote SQL Database Connection Issue

$
0
0

Hi

I am setting up an SCCM test environment and I have installed the WSUS server role on a Windows Server 2012 R2 server which also serves as my primary site server. I am running the database for SCCM and WSUS on 2 separate named instances on a SQL 2012 SP1 server.

I noticed in the add server roles wizard and in the post-deployment tasks that WSUS was unable to connect to the reserved instance unless I turned off the Windows firewall on the SQL server. However I can not seem to find which additional port I have to open for the WSUS server to be able to connect to the remote database.

So far, I have opened the following ports on my SQL server:

80, 8530 for HTTP connections

443, 8531 for HTTPS connections

1443 to test if the default port was used

50001 for the SCCM instance

50002 for the WSUS instance

50003 for the SQL Server Broker

Also port 135, 137, 139 and 445 are allowed.

In the add server roles wizard I got an error (provider: Named Pipes Provider, error: 40 - Could not open a connection to SQL Server). My guess here is that the wizard tries to connect using named pipes after trying  TCP/IP (I have disabled the use of named pipes).

Anyone that has any idea what additional port(s) I need to open? 

Thanks!





Change NETBIOS (Computer Name) of a computer under a domain controller by SCCM 2012 colsole

$
0
0

Is it possible to change NETBIOS (Computer Name) of a computer under a domain controller via SCCM 2012 Console?

example:

Domain Name: viyella.com

current Computer (FQDN host) name: vtgit-shohal.viyella.com

New Computer (FQDN host) name: vtgit-moin.viyella.com

if so, I will organized all computer of my organization and managed.

please help.

Thanks,

Shohal Bhuiyan


Shohal Bhuiyan

Endpoint Protection clients no getting updates from SCCM 2012 in new Secondary Site

$
0
0

I recently stood up a secondary site behind a PCI firewall to manage PCI in-scope systems. All of my boundaries are properly configured and there are no overlaps. I am able to push packages to these clients and the clients are reporting as healthy however I am not able to get updates to the SCEP clients. There is no internet access from these systems so I have to rely on updates from SCCM. From what I can see in the WindowsUpdate log it is only trying to go to Microsoft for the definitions. Here is the Log:

2014-04-3011:05:09:739 828da8MiscWARNING: Send failed with hr = 80072ee2.
2014-04-3011:05:09:739 828da8MiscWARNING: Proxy List used: <(null)> Bypass List used : <(null)> Auth Schemes used : <None>
2014-04-3011:05:09:739 828da8MiscWARNING: Send request failed, hr:0x80072ee2
2014-04-3011:05:09:739 828da8MiscWARNING: WinHttp: SendRequestUsingProxy failed for <HTTPS://sls.update.microsoft.com/SLS/{9482F4B4-E343-43B6-B170-9A65BC822C77}/x64/6.3.9600.0/0?CH=41&L=en-US&P=&PT=0x7&WUA=7.9.9600.16422>. error 0x80072ee2
2014-04-3011:05:09:739 828da8MiscWARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072ee2
2014-04-3011:05:09:739 828da8MiscWARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072ee2
2014-04-3011:05:09:739 828da8MiscWARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072ee2
2014-04-3011:05:09:739 828da8SLSFATAL: GetResponse failed with hresult 0x80072ee2...
2014-04-3011:05:09:739 828da8EPFATAL: EP: CSLSEndpointProvider::GetWUClientDataAndInitParser - failed to get SLS data, error = 0x80072EE2
2014-04-3011:05:09:739 828da8EPFATAL: EP: CSLSEndpointProvider::GetEndpointFromSLS - Failed to get client data and init parser, error = 0x80072EE2
2014-04-3011:05:09:739 828da8EPFATAL: Failed to obtain 9482F4B4-E343-43B6-B170-9A65BC822C77 redir SecondaryServiceAuth URL, error = 0x80072EE2
2014-04-3011:05:09:739 828da8AgentWARNING: Failed to obtain the authorization cab URL for service 7971f918-a847-4430-9279-4a52d1efe18d, hr=0
2014-04-3011:05:09:739 828da8AgentFATAL: Caller <NULL> failed to opt in to service 7971f918-a847-4430-9279-4a52d1efe18d, hr=0X80072EE2
2014-04-3011:05:09:739 828da8SLSRetrieving SLS response from server...
2014-04-3011:05:09:739 828da8SLSMaking request with URL HTTPS://sls.update.microsoft.com/SLS/{9482F4B4-E343-43B6-B170-9A65BC822C77}/x64/6.3.9600.0/0?CH=41&L=en-US&P=&PT=0x7&WUA=7.9.9600.16422
2014-04-3011:05:30:742 828da8MiscWARNING: Send failed with hr = 80072ee2.
2014-04-3011:05:30:742 828da8MiscWARNING: Proxy List used: <(null)> Bypass List used : <(null)> Auth Schemes used : <None>
2014-04-3011:05:30:742 828da8MiscWARNING: Send request failed, hr:0x80072ee2
2014-04-3011:05:30:742 828da8MiscWARNING: WinHttp: SendRequestUsingProxy failed for <HTTPS://sls.update.microsoft.com/SLS/{9482F4B4-E343-43B6-B170-9A65BC822C77}/x64/6.3.9600.0/0?CH=41&L=en-US&P=&PT=0x7&WUA=7.9.9600.16422>. error 0x80072ee2
2014-04-3011:05:30:742 828da8MiscWARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072ee2
2014-04-3011:05:30:742 828da8MiscWARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072ee2
2014-04-3011:05:30:742 828da8MiscWARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072ee2
2014-04-3011:05:30:742 828da8SLSFATAL: GetResponse failed with hresult 0x80072ee2...
2014-04-3011:05:30:742 828da8EPFATAL: EP: CSLSEndpointProvider::GetWUClientDataAndInitParser - failed to get SLS data, error = 0x80072EE2
2014-04-3011:05:30:742 828da8EPFATAL: EP: CSLSEndpointProvider::GetSecondaryServicesEnabledState - Failed to get client data and init parser, error = 0x80072EE2
2014-04-3011:05:30:742 828da8Agent  * WARNING: Online service registration/service ID resolution failed, hr=0x80248014
2014-04-3011:05:30:742 828da8Agent  * WARNING: Exit code = 0x80248014
2014-04-3011:05:30:742 828da8Agent*********
2014-04-3011:05:30:742 828da8Agent**  END  **  Agent: Finding updates [CallerId = System Center Endpoint Protection (DDEFDD14-250E-4DC8-A0B3-9D667EC5D8EB)  Id = 9]
2014-04-3011:05:30:742 828da8Agent*************
2014-04-3011:05:30:742 828da8AgentWARNING: WU client failed Searching for update with error 0x80248014
2014-04-3011:05:30:742 828da8IdleTmrWU operation (CSearchCall::Init ID 9, operation # 99) stopped; does use network; is not at background priority
2014-04-3011:05:30:742 828da8IdleTmrDecremented PDC RefCount for Network to 0
2014-04-3011:05:30:742 828da8IdleTmrDecremented idle timer priority operation counter to 0
2014-04-3011:05:30:743 57612c0COMAPI>>--  RESUMED  -- COMAPI: Search [ClientId = System Center Endpoint Protection (DDEFDD14-250E-4DC8-A0B3-9D667EC5D8EB)]
2014-04-3011:05:30:743 57612c0COMAPI  - Updates found = 0
2014-04-3011:05:30:743 57612c0COMAPI  - WARNING: Exit code = 0x00000000, Result code = 0x80248014
2014-04-3011:05:30:743 57612c0COMAPI---------
2014-04-3011:05:30:743 57612c0COMAPI--  END  --  COMAPI: Search [ClientId = System Center Endpoint Protection (DDEFDD14-250E-4DC8-A0B3-9D667EC5D8EB)]
2014-04-3011:05:30:743 57612c0COMAPI-------------
2014-04-3011:05:30:743 5761254COMAPIWARNING: Operation failed due to earlier error, hr=80248014
2014-04-3011:05:30:743 5761254COMAPIFATAL: Unable to complete asynchronous search. (hr=80248014)

The log is from a Server 2012 R2 Client. The only thing I was able to find was this Article which did not resolve my issue. Anyone else encounter anything similar? Any help would be appreciated.



Regards, Evan Mills - Systems Administrator

Manual uninstall of WSUS on Windows Server 2012

$
0
0

Good afternoon

I am really struggling getting software updates working on my SCCM server. I had SCCM and WSUS installed on the same server, I inherited this server when I joined the company. WSUS was working fine and clients were able to pull updates from it but after add the 'Software update point' role to my SCCM site this seems to screw up WSUS.

What I want to do is completely remove WSUS, including the WID and start from scratch (I don't want to get rid of my SCCM installation as this is working, although it doesn't work after I remove the WSUS role until I re-add it again).

I'm really stuck here!

Thanks

Issue with integer registry compliance settings

$
0
0

Hello,

I want to use compliance settings to make sure a registry key has a specific value. I successfully created the configuration item and configuration baseline, tested the deployment on a test collection and verified the setting is enforced.

My issue is with the way the registry value gets created if it doesn't exist. I configured a data type of 'Integer' and the value gets created as a REG_QWORD on 64-bits machines. What I want is a REG_DWORD otherwise the software using this value doesn't work as expected. I don't know if the issue is the same on 32-bits machines (I don't have one to test at the moment).

I played with the various data types available for registry values but I can't seem to find how to achieve my goal.

Thank you for your help.

Clarification of "Automatic Client Upgrade" in Hierarchy Settings

$
0
0

Hello all, I am looking for clarification of "Automatic Client Upgrade" in Hierarchy Settings.  I am SCCM 2012 R2 CU1.  It says the latest version is "5.00.7958.1000"  My CU1 version is actually "5.00.7958.1203".  From reading various other users forum questions regarding this issue I have learned that this upgrade will only work for "Major versions".  That should be why I don't see the same versions.  My question relates possibly more generally. 

I am in the process of building and configuring the SCCM 2012 R2 CU1 (site code: IT1) environment.  I have a running production SCCM 2007 R3 (site code:  IT0) environment, with a different side code.  I am not ready for these older SCCM 2007 R3 clients to be upgraded to SCCM 2012 R2 CU1 as I am still testing and finalizing things. 

If I enable the "Automatic Client Upgrade" in Hierarchy Settings for 2012 R2 CU1, could someone better explain which clients this affects?

  1. Will it upgrade my old SCCM 2007 R3 clients to SCCM 2012 R2? 
  2. Will it upgrade anything outside of the SCCM 2012 site IT1 (if I had two SCCM 2012 sites with different names)?
  3. Will it upgrade an SCCM 2012 client to SCCM 2012 R2?
  4. Will it upgrade an SCCM 2012 SP1 CUx client to SCCM 2012 R2?
  5. Will it upgrade an SCCM 2012 R2 client to SCCM 2012 R2 CU1?  (from what I have read, NO)

Find this post helpful? Does this post answer your question? Be sure to mark it appropriately to help others find answers to their searches.

Updates - In Progress Non-Compliant

$
0
0

I have a Win 7 software update group that I have pushed out to several clients. Many of them come back successful, but I have some that are In Progress with a status of Non-Compliant.

I am trying to determine the best flow to troubleshoot this issue. When I look at the asset details on the client in the deployment and it lists all the updates under the software Updates tab, I can see a list of all the updates and what's installed and what is listed as required. However, these updates are a part of the software update package, so I am little bit lost on why it isn't just downloading and installing them. When I look at this on all the systems having the same problem, it isn't consistently the same updates on each one.

Also, since pushing out the updates, I see it's downloaded several in the ccmcache, so it is receiving that information and downloading from the DP.


Method to view what files or processes SCEP is scanning in Realtime?

$
0
0

In the last few days SCEP has started using up 20-40% CPU on a computer constantly. I have been having trouble identifying what program the real-time scanning is interacting with to cause this unexpected behavior. Does anyone know of a log or other method to view the processes being scanned by the real-time protection for the purpose of identifying whether an exclusion needs to be made?

Normally I will look through task manager for another process that is taking up a lot of CPU or performing a significant amount of disk activity to see if a correlation becomes obvious, but in this case I can't find anything other than SCEP itself.


What does SCCM Patch Status "Downloaded update" mean?

$
0
0
What does SCCM Patch Status  "Downloaded update" mean?

ADR Rules Hits 60% updates for Endpoint Protection

$
0
0

Hi,

I have an ADR rule that is working correctly, the only thing its not hitting is all the servers for the Updates of the AV, I have about a 60% success rate.

I have checked my policies and everything is the same, I have some servers in the same collection not updating the AV an the have the exact same policies and in the same site controlled by the same management point and Distribution Point same Domain.

Can you assist me in telling me where to check what is the blockage of the updates, My ADR rules are running fine no errors in the ruleengine.log, I seem to constantly fix this issue and cant find the issue,

any assistance will do.

How to Disable SCCM Software Updates on Client Workstations

$
0
0

Hi,

I have enabled Software Updates for all clients, to create a baseline for reporting. The intent was to then disable Software Updates via. SCCM Client Settings, so that our clients could continue receiving updates from Microsoft until we were ready to deploy updates to our clients.

After modifying the SCCM Client Settings, the Software Update Cycles/actions removed from the Configuration Manager Client on the workstations, however the local policy on the workstation remained configured (did not revert back to Non-Configured).

and the workstation is still looking to the SCCM for Windows Updates.

Using SCCM, how do I get the workstations back to Microsoft for Windows/Microsoft Updates?

TIA,
Bill



Endpoint not removing Microsoft Security Essentials

$
0
0

Hi there,

We're using SCCM 2012 SP1 CU3 and deploying Endpoint. Endpoint is not installing though. In our client settings the Endpoint Protection component "Automatically remove previously installed antimalware software before Endpoint Protection is installed"is set to YES

When I look in the logs in EndpointProtectionAgent.log there is this message:

System Center Endpoint Protection installation error. One or more programs on your computer conflict with System Center Endpoint Protection.To install System Center Endpoint Protection, you must remove the following programs and then run the installation wizard again. Error code:0x8004FF52. Programs: Microsoft Security Essentials

That surprises me, as the following Microsoft page - http://technet.microsoft.com/en-us/library/4acd0c29-e453-4863-8194-e479263291c8 clearly shows that "Microsoft Security Essentials v1" will be uninstalled.

The version of Microsoft Security Essentials on our client machines is 1.0.2498.0

Any idea why this is not working?

Thanks,

Kieran.

Pushing out two updates with one being a requisite.....

$
0
0
I am in the midst of pushing out the recent update KB2964358 for the recent IE vulnerability.  I have 42 machines that also need KB2929437 (as IE will crash on these machines if it is not installed).  My question is this: if I lump both updates into one package and push it out, will SCCM know to install the prerequesite first or do I need to roll out KB2929437 separately?  Thanks!

Get clients to install KB2964358 quickly from Software Updates

$
0
0

The update has already been synchronized in SCCM 2012. A new Automatic Deployment Rule has been created and set to "as soon as possible". How quickly will the clients get the update?

Thanks

Software updates available from what date

$
0
0

When we synchronize software updates for e.g for Windows 8.1 or 2008 R2. From which year are those updates available ?

For e.g Are there security updates available from year 2005?


SUP Client Installation and GPO Impact after client is installed

$
0
0
I am installing the SCCM 2012 SP1 client via SUP and GPO.  I have enabled "Configure Automatic Updates" and set it to download and schedule an install.  The specified server is the SUP server...no problem. The GPO is applied to servers in the domain.  What is the impact to the SCCM client with the "Configure Automatic Updates" set as scheduled after the client is installed.  Will that GPO setting take precedence over the SCCM Deployment Schedules?  Will the GPO "Configure Automatic Updates" setting need to be removed after the initial client installations?  If so, how do you maintain SUP client installs?  Thank you for your help!! 

HOWTO: Specific roles for specific users

$
0
0
I see that there are pre-made security roles already in SCCM 2012, but I don't see an option for me to create specific security roles. I want to create a role where only certain members in my department are able to just see devices to delete them so that they can reimage machines through PXE. Other then that, I don't want them touching anything else like the system image, applications, etc. How can I set this up?

SCCM 2012 SCEP will not apply to Windows 7 32 bit machines

$
0
0

Here is the log from EndpointProtectionAgent.log

<![LOG[start to send State Message with topic type = 2001, state id = 2, and error code = 0x00000000]LOG]!><time="13:36:55.935+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentimpl.cpp:1326">
<![LOG[Start to send state message.]LOG]!><time="13:36:55.935+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentutil.cpp:1246">
<![LOG[Send state message successfully]LOG]!><time="13:36:55.959+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentutil.cpp:1248">
<![LOG[Failed to get EP event code under registry key SOFTWARE\Microsoft\CCM\EPAgent]LOG]!><time="13:36:55.959+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="2" thread="10684" file="epagentimpl.cpp:1351">
<![LOG[Failed to get EP event message under registry key SOFTWARE\Microsoft\CCM\EPAgent]LOG]!><time="13:36:55.959+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="2" thread="10684" file="epagentimpl.cpp:1356">
<![LOG[Save new state 2, error code 0, detail message '' to registry SOFTWARE\Microsoft\CCM\EPAgent\State]LOG]!><time="13:36:55.961+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentimpl.cpp:229">
<![LOG[File C:\Windows\ccmsetup\SCEPInstall.exe version is 4.3.220.0.]LOG]!><time="13:36:55.998+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentutil.cpp:519">
<![LOG[EP version 4.3.220.0 is already installed.]LOG]!><time="13:36:55.998+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentutil.cpp:232">
<![LOG[Expected Version 4.3.220.0 is exactly same with installed version 4.3.220.0.]LOG]!><time="13:36:55.998+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentutil.cpp:251">
<![LOG[start to send State Message with topic type = 2001, state id = 3, and error code = 0x00000000]LOG]!><time="13:36:55.998+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentimpl.cpp:1326">
<![LOG[Start to send state message.]LOG]!><time="13:36:55.998+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentutil.cpp:1246">
<![LOG[Send state message successfully]LOG]!><time="13:36:56.006+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentutil.cpp:1248">
<![LOG[Sending message to external event agent to enable notification]LOG]!><time="13:36:56.006+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentutil.cpp:914">
<![LOG[Sending message to endpoint ExternalEventAgent]LOG]!><time="13:36:56.006+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentutil.cpp:1146">
<![LOG[Sending message to external event agent to execute all on demand actions.]LOG]!><time="13:36:56.011+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentutil.cpp:988">
<![LOG[Sending message to endpoint ExternalEventAgent]LOG]!><time="13:36:56.011+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentutil.cpp:1146">
<![LOG[Save new state 3, error code 0, detail message '' to registry SOFTWARE\Microsoft\CCM\EPAgent\State]LOG]!><time="13:36:56.021+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentimpl.cpp:229">
<![LOG[Handle EP AM policy.]LOG]!><time="13:36:56.021+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="fepsettingendpoint.cpp:183">
<![LOG[Apply AM Policy.]LOG]!><time="13:36:56.021+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentimpl.cpp:1209">
<![LOG[Create Process Command line: "c:\Program Files\Microsoft Security Client\\ConfigSecurityPolicy.exe" "C:\Windows\CCM\EPAMPolicy.xml".]LOG]!><time="13:36:56.061+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentutil.cpp:607">
<![LOG[Failed to create process c:\Program Files\Microsoft Security Client\\ConfigSecurityPolicy.exe with error = 0x80070002.]LOG]!><time="13:36:56.061+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="3" thread="10684" file="epagentutil.cpp:621">
<![LOG[Failed to apply policy with error 0x80070002, retry number : 1 after 60 second.]LOG]!><time="13:36:56.061+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentimpl.cpp:707">
<![LOG[Endpoint is triggered by WMI notification.]LOG]!><time="13:36:56.439+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10212" file="fepsettingendpoint.cpp:154">
<![LOG[Endpoint is triggered by message.]LOG]!><time="13:36:57.305+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="212" file="fepsettingendpoint.cpp:58">
<![LOG[Create Process Command line: "c:\Program Files\Microsoft Security Client\\ConfigSecurityPolicy.exe" "C:\Windows\CCM\EPAMPolicy.xml".]LOG]!><time="13:37:56.064+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentutil.cpp:607">
<![LOG[Failed to create process c:\Program Files\Microsoft Security Client\\ConfigSecurityPolicy.exe with error = 0x80070002.]LOG]!><time="13:37:56.064+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="3" thread="10684" file="epagentutil.cpp:621">
<![LOG[Failed to apply policy with error 0x80070002, retry number : 2 after 60 second.]LOG]!><time="13:37:56.064+240" date="05-02-2014" component="EndpointProtectionAgent" context="" type="1" thread="10684" file="epagentimpl.cpp:707">

Any thoughts?

WQL for systems with an update installed

$
0
0

Hello,

I am working on trying to get an update out but need to make sure the pre-req is installed first, but WSUS/SUP doesn't validate the applicability of the update so the pre-req doesn't install, which causes a lot of other issues. So, as to not be super specific about the updates being applied I am going to use 2 random ones that really have nothing to do with each other to explain.

Collection 1 (Pre-Req): Install KB2737954

Collection 2 : Install KB2798162

Collection 1 consists of All Systems, Collection 2 Consists of systems with KB2737954 installed and also limited to Collection 1. This is the query I am using, which isn't returning anything:

select SMS_R_SYSTEM.ResourceID,SMS_R_SYSTEM.ResourceType,SMS_R_SYSTEM.Name,SMS_R_SYSTEM.SMSUniqueIdentifier,SMS_R_SYSTEM.ResourceDomainORWorkgroup,SMS_R_SYSTEM.Client from SMS_R_System inner join SMS_G_System_INSTALLED_SOFTWARE on SMS_G_System_INSTALLED_SOFTWARE.ResourceId = SMS_R_System.ResourceId where SMS_G_System_INSTALLED_SOFTWARE.ARPDisplayName like "%KB2737954%

This is the "like" sql query of it, which returns 9 machines.

SELECT gcs.Name0, garp.DisplayName0

FROM v_GS_COMPUTER_SYSTEM gcs
	JOIN v_GS_ADD_REMOVE_PROGRAMS garp ON gcs.ResourceID = garp.ResourceID

WHERE garp.DisplayName0 LIKE '%KB2737954%'

 Could someone help me convert this to WQL?

SCCM2012 report with IE version for Win7 PC

$
0
0
Hi team, need some advice from you,thanks! I have SCCM2012 client push out to some win7 pc, and the default setting of client setting is to enable software update. so this might cause some win7 pc upgrade IE to version 11 from v8 or v9. while some applications don't work with v10 or above. I need to generate a report for these PC and downgrade them to IE8. I found some queries of sccm2007 but it seems not working directly on sccm2012. any advice on this? I need to generate a report for win7 PC only and only for those IE version is 10 or 11, with computer name,last logon user name. So that we can find those users when we need downgrade the IE. And also need to creat a collection which show only win7 pc which IE version is  11. so that later on we can downgrade IE for this collection. Any advice please? Currently I did a query to show PC with IE 11 but it's blank. I chose one PC which I did see that has IE11 upgraded, ran start resource explorer, under hardware---  installed applications, I could not see any Internet explorer at all,neither in other catagories,like "installed executable",etc. Is it because IE now because a kind of windows update instead of an installed program? any way to list down in the report or query?Many thanks!

Thanks and best regards, -- KF

Viewing all 6382 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>