Showing posts with label sccm. Show all posts
Showing posts with label sccm. Show all posts

Monday, February 13, 2017

Software Updates that require multiple reboots

Ever have the problem of a software update installing only to find out that you need the next one and the next one.  By the time you are finished it has required several restarts. This can cause a problem for your users if they are restarting every day or left for the day and another patch restart occurred.





Now available in 1610, you can force the client to rescan and update if necessary.  This is not enabled by default when you upgrade.  You will need to revisit your Software Updates / Servicing Updates deployments and enable this.  Also, you will need to update your ADR so that all future updates will also have this feature installed. 


This is especially critical when a machine needs several office or .Net patches that require restarts before the next update can install.

Monday, June 15, 2015

Make your voice heard

Microsoft has several ways to pull in feedback, MVPs, forums, Microsoft Connect.  Here is another method to interact with Microsoft without having to fill out the complex Design Change Request.

Ask Microsoft what you would like to see or vote (up to 10x) on a topic.  If that topic is already in production or complete then your vote should be turned back to you to use again. 
Remove and change your votes as new ideas are submitted:


Here’s how it will work:

For ideas/DCRs only (no bugs) for Configuration Manager:


 

For Intune standalone, and ConfigMgr+Intune hybrid MDM (Bugs and DCRs):

Friday, June 21, 2013

Description of Cumulative Update 2 for System Center 2012 Configuration Manager Service Pack 1

http://support.microsoft.com/kb/2854009

Microsoft has publicly announced the availably of CU2 for ConfigMgr 2012 Sp1.

I will let you read the information for yourself but it fixes several issues for us.

CU1: Alternate port download for Windows update
CU2: Imaging over Alternate ports and BGB issue when using Custom Websites.

Like Cu1 you will need to have an update to the client pushed as well as an update to the Task Sequence for the client.

One thing I will need to test with this release is the need to repush the Boot.wim.  This would be necessary for the companies running over alternate ports.  It is also a good practice to create new boot media for your machines.

I hope to have this fully tested soon but none of what I have suggested is destructive to your enviroment. 
 

Tuesday, June 18, 2013

Console Extension Commands

In previous posts I have detailed different ways to create console extensions.  We have seen in 2003, 2007 and now in 2012, how to pass the parameters.  Here I have listed the commands per the different panels.  While some can be used in others, I have decided to break it down to make it easier to understand where each came from.  In a future post I will tell you how use can use the GUID Extension finder (first made famous by Greg Ramsey) as a way to export the data for each GUID you see here.

AssetManagementNode
##SUB:Name##
##SUB:ResourceType##
##SUB:ResourceID##
##SUB:ThreatName##
##SUB:IsBuiltIn##
##SUB:CollectionID##
##SUB:FeatureType##
##SUB:CategoryName##
##SUB:Description##
##SUB:CommonName##
##SUB:Product##
##SUB:ProductName##
##SUB:LocalizedDescription##
##SUB:IsBroken##
##SUB:IsEnabled##
##SUB:SoftwareName##
##SUB:CollectionName##
##SUB:CI_ID##
##SUB:SettingsID##
##SUB:LocalizedDisplayName##

ConnectedConsole
##SUB:ADSiteName##
##SUB:ForestID##
##SUB:ADSubnetName##
##SUB:CategoryName##
##SUB:Description##
##SUB:CommonName##
##SUB:Name##
##SUB:PackageID##
##SUB:NALType##
##SUB:NALPath##
##SUB:NVD:ConnectedSiteCode##
##SUB:RoleName##
##SUB:FeatureType##
##SUB:AssignmentID##
##SUB:PolicyModelID##
##SUB:StatusType##
##SUB:DTCI##
##SUB:EnforcementState##
##SUB:AppStatusType##
##SUB:ErrorCode##
##SUB:DTResultID##
##SUB:RuleID##
##SUB:RequirementName##
##SUB:CollectionID##
##SUB:Category##
##SUB:Value##
##SUB:GroupID##
##SUB:BoundaryID##
##SUB:USR:ChClientsCondition##
##SUB:ResourceType##
##SUB:ResourceID##
##SUB:DeploymentID##
##SUB:MessageID##
##SUB:IsBuiltIn##
##SUB:SoftwareName##
##SUB:MessageCategory##
##SUB:SummaryType##
##SUB:AssetID##
##SUB:AssetType##
##SUB:ObjectID##
##SUB:ObjectType##
##SUB:CI_ID##
##SUB:ErrorType##
##SUB:Rule_ID##
##SUB:RuleSubState##
##SUB:SiteCode##
##SUB:Type##
##SUB:ComponentName##
##SUB:LocalizedDisplayName##
##SUB:LocalizedDescription##
##SUB:HasContent##
##SUB:IsExpired##
##SUB:ModelName##
##SUB:Technology##
##SUB:CollectionName##
##SUB:ProgramName##
##SUB:ServerName##
##SUB:Drive##
##SUB:Bucket##
##SUB:USR:ClassNameVar##
##SUB:USR:CollectionIDVar##
##SUB:USR:ConditionVar##
##SUB:ThreatName##
##SUB:ID##
##SUB:TypeInstanceID##
##SUB:MemberClassName##
##SUB:IsDirect##
##SUB:CI_UniqueID##
##SUB:IsBroken##
##SUB:IsEnabled##
##SUB:EulaExists##
##SUB:AssignmentName##
##SUB:AssignmentDescription##
##SUB:NV:MonitoringCollectionName##
##SUB:USR:MonitoringStickyQuery##
##SUB:NV:ConnectedSiteCode##
##SUB:USR:NodeName##
##SUB:USR:NodeDesc##
##SUB:NV:AlertSeverityName##
##SUB:USR:Severity##
##SUB:SMSID##
##SUB:Expression##
##SUB:__CLASS##
##SUB:_RoleDescription##
##SUB:USR:SiteCodesCondition##
##SUB:StatusEnforcementState##
##SUB:StatusErrorCode##
##SUB:DeviceID##
##SUB:ThreatID##
##SUB:NVD:ShowSearchTab/False##

ManagementClassDescriptions
##SUB:SiteCode##
##SUB:SiteName##

MonitoringNode
##SUB:Name##
##SUB:ID##
##SUB:Comments##
##SUB:Description##
##SUB:Role##
##SUB:NV:ConnectedSiteCode##
##SUB:ComponentName##
##SUB:NVD:ComponentStatusTallyInterval/0001128000100008##
##SUB:SoftwareName##
##SUB:CollectionName##
##SUB:FeatureType##
##SUB:PrimaryActionType##
##SUB:State##
##SUB:SiteType1##
##SUB:SiteType2##
##SUB:site1##
##SUB:site2##
##SUB:NALPath##
##SUB:WSUSServerName##
##SUB:ThreatName##
##SUB:CollectionID##
##SUB:ThreatID##

SiteConfigurationNode
##SUB:Name##
##SUB:Description##
##SUB:NVD:ConnectedSiteCode##
##SUB:ComponentName##
##SUB:Value##
##SUB:SiteType1##
##SUB:SiteType2##
##SUB:SiteName##
##SUB:NV:ConnectedSiteCode##
##SUB:AddressType##
##SUB:ForestFQDN##
##SUB:ForestID##
##SUB:ServiceCName##
##SUB:Type##
##SUB:NALType##
##SUB:RoleName##
##SUB:_RoleDescription##
##SUB:NALPath##
##SUB:SettingsID##
##SUB:LogonName##
##SUB:IsCovered##
##SUB:IsBuiltIn##
##SUB:CategoryName##
##SUB:UserName##
##SUB:_ItemDescription##
##SUB:IssuedTo##
##SUB:Drive##
##SUB:SourceSiteFQDN##
##SUB:SourceSiteCode##
##SUB:JobName##
##SUB:JobID##

SoftwareLibraryNode
##SUB:LocalizedDisplayName##
##SUB:LocalizedDescription##
##SUB:HasContent##
##SUB:IsExpired##
##SUB:CI_UniqueID##
##SUB:Technology##
##SUB:ModelName##
##SUB:Name##
##SUB:Description##
##SUB:ProgramName##
##SUB:PackageId##
##SUB:FeatureType##
##SUB:Application##
##SUB:Comments##
##SUB:IsReadOnly##
##SUB:InUse##
##SUB:EulaExists##
##SUB:AssignmentName##
##SUB:AssignmentDescription##
##SUB:CI_ID##
##SUB:Version##

Saturday, June 15, 2013

VHD creation for ConfigMgr 2012 R2

Recently Microsoft has been unveiling the enhancements that will be seen in System Center 2012 Configuration Manger.

http://www.microsoft.com/en-us/server-cloud/system-center/system-center-2012-r2-configuration-manager.aspx

The goal of the VHD creation for R2 is to help you with VMM, having a unified approach to image creation.  Now you can update your VHD by simply changing a task sequence.  That's nice but what about the undocumented benifit.

Windows 8 has a hyper-V functionality.  So what?  Well generally you create your Corporate Image and then start pushing to hardware, some might even push it to a hyper-V server to load and allow people to look at.  Well now you can cut testing time by creating a VHD, shoot it over to the VM farm for testing or maybe even just allow Win8 users to pull down the VHD, install it on their machine and run all the testing on their own virtual environment.  While this is happening the Imaging team can also then work on the Hardware drivers and other items necessary for deployment.  Then the real Hardware testing can be done while other are still testing the data portion in a VHD.  Then you have a real world deployment and testing. 

This could, in affect, quicken the testing and deployment of an image utilizing the Win8 and R2 system.  Test Win 8.1 in this manor before sending it out.  This way you don't even need to install it to your machine, you have the corporate image VHD created and apply 8.1 and test your applications.

Thank you Microsoft for allowing the IT professionals an easier way to test and deploy IT standards!!!!

Later we will show this in a Task Sequence.

Friday, May 17, 2013

Locating a broken Software Update package


Scenario:

Onsite complains that the machine hangs when installing patches during imaging (or all machines for a given patch).  It could also be that the user has the dialog box for Software Update but it continually says "failed"
 

Solution:

1. Location the machine name
2. Open Status Messages for the given machine.  Locate the patch that failed, assuming the status message was sent back. 
    In 2007: System Status -> Status Message Queires - > all Status Message from a specific Machine
    in 2012: Monitoring Pane -> All Status Messages from a Specific System
3. Type in the machine name, time range and select OK.  A faster way is a right click tool I created a while back (http://www.sccm-tools.com/tools/rightclick/Rightclick-statusmessages.html) I don't have this in 2012 yet.  I need to also update my tools site to support 2012, look for the changes.
 

 
 
Locate this line:

Bundle update "93fa39c7-1f23-4549-b3ba-71021177bcc4" failed to get content for update "2cefe0ef-f4e1-4c3d-97f9-10a608c46c52". Please check the enforcement status of update "2cefe0ef-f4e1-4c3d-97f9-10a608c46c52" to get further details. The operating system reported error 2147500036: Operation aborted
 
If we pull the updateid "2cefe0ef-f4e1-4c3d-97f9-10a608c46c52" you can hunt for the specific update.  In this case you need to open your Content Location folder and search your Microsoft Updates for the folder..
 
 
Here we can see this is from the Q2 updates for the 2013 patches from the year of 2013. 
 
From here there are several things you can do:
1. remove the update frrom the DP and then repush
2. Refresh the package on the DP.
3. Delete the update and redownload (Provision) it from Microsoft and repush.
 
The end result should be the same.  Hopefully you can back track the bad update and fix it.
 
Note:  This assume you have already determined there are problems with the source and not the machine.  This can be determined by uninstalling the update from a machine and attempting to reinstall it or seeing all machines pulling from the given DP with errors.
 

Saturday, April 6, 2013

2012 Console Extensions for 2012 SP1 Cu1

So I have been a bit busy lately with my 2012 Migration.  You have seen last year that I produced all the xml folders and files for the 2012 RTM extensions.  Well here is the updated version all the way up to CU1.  I haven't looked to see any of the Guids changed in CU1 but I wanted to make the note incase something did change.  If you try this on your Sp1 system and you are missing some guids, please drop me a line and I will see if I can spin up a 2012 SP1 site and export the guids. 

Realize that not all Guids are accessible, even if I have them listed.  What I am simply doing is pulling out all GUIDS the Microsoft references.  Nodes that are created on the fly when you click Show members don't have a guid and can't be accessed because they are dynamic nodes and are destroyed when you navigate away.

Please see this post to add images: http://sms-hints-tricks.blogspot.com/2012/04/console-extensions-2012-xml-insites.html

Also reference in the SDK are console extensions and how to add images and further manipulate the console.  http://msdn.microsoft.com/en-us/library/hh949463.aspx

Console files should be added here :
%ProgramFiles%\Microsoft Configuration Manager\AdminConsole\XmlStorage\Extensions\Actions\<GUID> folder, where <GUID> is the GUID identifier for the node that the action applies to.

Be aware that the console doesn't abide by file extensions so you can call the file .XXX and the console will still attempt to load it.  If you don't want it loaded then you should create a sub folder and then The console will ignore it. 

Please DO NOT install this on a production box.  The 620 console extensions here can cause the console to be slow or have problems.  I have broken down the folders into the different workspaces referenced.  Not all GUIDS will work, I simply export what Microsoft has.  If you find a problem with the same GUIDS you will need find the offending folder and delete it. 

The zip file can be downloaded here : 2012SP1CU1 Actions

Play responsibly :)

Thursday, October 27, 2011

ConfigMgr 2012 RC Released

Configuration Manager 2012 RC has been Released.

Just another step closer to RTM and to full deployment

One thing everyone should note is the Endpoint Protection is not included in the installer:

"System Center 2012 Configuration Manager and System Center 2012 Endpoint Protection are now provided as a single installation package"

http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=27841

Reprinted from Microsoft:Please note: System Center 2012 Configuration Manager and System Center 2012 Endpoint Protection are now provided as a single installation package.
System Center 2012 Configuration Manager helps you to empower people to use the devices and applications they need to be productive, while maintaining corporate compliance and control. As more and more consumer devices enter the workplace, IT faces the challenge of delivering a rich experience to users across multiple devices – both personal and corporate-owned – without giving up the control needed to protect company assets. Configuration Manager provides a unified infrastructure for mobile, physical and virtual environments. Configuration Manager also helps you to be more efficient with simplified administrative tools and improved compliance enforcement.

New features in the release candidate include:

•Improved endpoint protection functionality, with integrated setup, management and reporting of System Center 2012 Endpoint Protection. (see below)
•Improved application catalog design that provides a better, more responsive experience when requesting and downloading applications.
•New support for Windows Embedded devices, including Windows Embedded 7 SP1, POS-Ready 7, Windows 7 Think PC, and Windows Embedded Compact 7.
•Improved compliance enforcement and tracking, with the ability to create dynamic collections of baseline compliance and generate hourly compliance summaries.
•Platform support for deep mobile device management of Nokia Symbian Belle devices. Pending a platform update by Nokia later this calendar year for these devices, customers will be able to try out the management of Nokia devices with Configuration Manager.

System Center 2012 Endpoint Protection (previously known as Forefront Endpoint Protection 2012) protects client and server operating systems against the latest threats using industry-leading malware detection technologies. It is built on System Center 2012 Configuration Manager, giving customers a unified infrastructure for client security and compliance management. This shared infrastructure lowers ownership costs while providing improved visibility through user-centric malware reporting and control over endpoint management and security.

New features in the release candidate include:
•Support for System Center 2012 Configuration Manager, including integrated setup, management, and reporting.
•Role-based management across security and operations.
•Improved alerting and reporting, with near real-time and user-centric data views.
•More efficient delivery of signature updates using new automatic software deployment model.

Wednesday, May 18, 2011

SCCM 2007 Performance Considerations

Many times in the forum you will see administrators ask how to setup their hard disk arrays for best performance with SCCM. While this is not approached directly in the ConfigMgr documenation it is understood that you should always install the Configuration Manager application on a different drive than your OS. With that in mind, Microsoft has a document that will help with performance considerations for sites between 10,000 and 200,000 machines. If you are running a site less than 1,000 machines you could easily install everything on one drive and not see performance degredation but I would not consider is a best practice.

What is great about this document is the detailed information on Volumes, Raid type and number of disks.

10k clients (Single machine) Configuration
Site Server / management point:
* 2x2 Xeon @ 3 GHz
* 4GB RAM
* SAS write back / read ahead cache (with battery backup) options for all volumes

VolumePurposeRAID Type# of Disks
1Operating System/SQL Server Temp DatabaseRAID 12
2Configuration Manager 2007 installation files and SQL Server site databaseRAID 12

This document and other valuable White papers can be found here:
http://www.microsoft.com/systemcenter/en/us/configuration-manager/cm-white-papers.aspx



Exact white paper:
Configuration Manager 2007: Sample Configurations and Common Performance Questions

Please note that the document was created in July 2008 but still contains valuabe information that can be used today! Microsoft cannot keep up with every change in Disk and CPU technology so please adjust as necessary. For this reason Microsoft cannot recommend how to setup every different enviroment because there is no way of knowing the performance of your hardware.


Thursday, July 15, 2010

ConfigMgr site from Eval to Production

This question comes up in the forums frequently. Most people ask. I have setup a ConfigMgr server and I like it, how can I move this to production. If you have search the forums and docs then you see many people have done it. Here is the supporting Microsoft Docs
http://technet.microsoft.com/en-us/library/bb693584.aspx

By simply doing an in place upgrade on the site it will pull in your Key and other info and change the site to a production version. It isn't a quick install. Depending on how complex you have setup on the server it might take an hour or more.

I recently ran into this when another IT Admin called me and ask me to look at his site. The server patched at 3AM and when he checked it the next morning there were some errors and the Site wouldn't attach to the database. Well I have seen several errors like this so I headed on over. I looked at the log and found the one error you don't really expect to see in the Event log. "You 180 Evaluation of Configuration Manager has come to an end" It just so happened to have done this just after the patches were installed. So 5 mins to find the problem. About 1 hour or more waiting for the upgrade to occur. The person who had setup the site had left and the current admin didn't know that the site was an Eval. We put in the licensed CD for ConfigMgr and told it to upgrade the site. After a while of watching progress bars the site wanted a restart and then we check and it was all happy. The admin was grateful for my assistance and I admit that this was the first time I personally had ever performed an Eval to production move. I think if I wasn't there he might have formatted and started over. He is just now getting into ConfigMgr and is not an expert, nor is that is only job area. If you don't spend you life in ConfigMgr like I do then you are greatfull to the ones that do.

When the problem looks like the world is coming to an end, ask another IT person, forum, phone, directly. No one can learn unless you ask, and failing is the only way to truly learn. I know I have failed and stumbled many times. It is a part of life and no one should be too proud to say, "I don't know how to do that.". Especially in IT. I had no idea how to do a Pivot table until someone asked me to show them how. I told them I didn't know but I would look it up and figure it out and we can both work on it.

Have a good evening.

Saturday, May 1, 2010

System Center Configuration Manager 2007 Toolkit V2

Microsoft has release an update to the popular Configuration Manager Tool Kit. Added to the popular took kit are the following tools:

Delete Group Class, MP Troubleshooter, Preload Package and Send Schedule Tools

These were in the SMS 2003 toolkit but not in the 2007 version. Since the community requested them, Microsoft has delivered. Even while they give tools for ConfigMgr 2007 they are working on V.Next. This release has a nice MSI to make it easy to install and deploy if necessary.

Remember that SMS 2003 Mainstream support has now ended. Users should look at moving to 2007 and then to V.Next. If you're on 2003 the jump to V.NExt might be a bit much. Especially if you will wait for SP1. If you do then you might want to get over to ConfigMgr 2007 Sp2 R2. R3 will be release by the end of the year.

The download can be found here
http://www.microsoft.com/downloads/details.aspx?FamilyID=5a47b972-95d2-46b1-ab14-5d0cbce54eb8&displaylang=en

Monday, January 26, 2009

ConfigMgr 2007 VHD

Here is a link to the Configuration Manger 2007 VHD. Use any of the Micrsoft Virtual Machine programs to pull in this file. Now you can test and evaluate SCCM to see what you think.

You might noticed that there was a VHD a while back but the link died. Here is your chance to pull it down. It is quite large and seperated into parts.

http://www.microsoft.com/downloads/details.aspx?familyid=e0fadab7-0620-481d-a8b6-070001727c56&displaylang=en&tm

HAVE FUN!!!!

Monday, September 15, 2008

update to www.SCCM-tools.com

Well I have made some changes to my site http://www.sccm-tools.com It should be more firefox friendly. I needed to make some changes to the CSS and the Ajax. Take a look and play with the site.

Thursday, August 28, 2008

SCCM Tools

Well I have decided to launch my own website / community. Bascially I will host a site where users can request SCCM tools, download SCCM tools, and have discussions about creating tools.

http://www.sccm-tools.com

Is the URL. I hope to have the site up in the next few weeks. This site will be a beta test so people can just go wild on the site to see what needs to be improved. Then I will delete everything and launch the site. Lets hope it goes well. It isn't easy to launch and IT site for IT people, we are very picky. I can't match myITforum but I don't want to compete with them but work along side. I am hoping this fills a niche where people can locate tools. It seems to be a common question "Where can I find SCCM tools" Where there are my blogs and many places to get them. This won't house all the tools but will have links to those that we can't or don't want to host. There more diverse places you have to download programs the more likely you are to have an older version. So this way we can link to SourceForge or someother "original" location so the author doesn't need to police the we. Nor do we need to hunt for the latest release

Wednesday, June 11, 2008

Client actions for an entire collection

This page still isn't displaying correclty.
Here is a link on the SCCM tools website
http://www.sccm-tools.com/tools/rightclick/rightclick-clientactions.html


Ok I have deleted this whole section since I re-wrote this tool...

Files: (files names are case sensative)
clientactions.vbs : File that controls everything
Clearcache.vbs : Client clear cache file
Inventory.vbs: Client HW/SW inventory file
Policy.vbs: Client machine policy refresh
Computer.XML : This will be the xml file for right click on a computer
Collection.XML: This will be the xml file for right click on a collection
C:\Program Files\MCNS\ClientActions\ : Location where all the files are stored on the server

7ba8bf44-2344-4035-bdb4-16630291dcf6 - computers
fa922e1a-6add-477f-b70e-9a164f3b11a2 - this GUID is for first-level collections
dbb315c3-1d8b-4e6a-a7b1-db8246890f59 - this GUID is for all subcollections
---
x:\Program Files\Microsoft Configuration Manager\AdminUI\XmlStorage\Extensions
Under this folder create the guid and place the appropriate XML file
-------------------------------------------------------------------------
******Clientactions.vbs***************

******Clearcache.vbs***************



******Inventory.vbs***************



******Policy.vbs***************



******Computer.XML***************



******Collection.XML***************

Tuesday, March 18, 2008

SCCM SDK

The Configuration Manager 2007 Software Development Kit (SDK) has been released and is now available on the Microsoft Download Center:

http://www.microsoft.com/downloads/details.aspx?FamilyId=064A995F-EF13-4200-81AD-E3AF6218EDCC&displaylang=en

This concludes the beta program for this release. Please discontinue use of and remove all copies of the pre-release builds.

Thank you for your participation and feedback.
-ConfigMgr SDK Team-

Wednesday, March 5, 2008

SCCM Collections with apostrophes '

In SMS you could have a collection with an apostrophe but in SCCM you currently can't do limited queires based on the collection.

Example:

Example 1
Collection: Bob's Department
Limted: Not limited
Query:xxxxxxxxxx

Example 2
Collection: Departments
Limted: Bob's Department
Query:xxxxxxxxxx

If you created a collection with a limit based on a collection that has an apostrophe the Admin UI will crash. Sorry. Hopefully this will be corrected in SP1. This had to do with passing the characters safely.

Thursday, February 14, 2008

SCCM Client Certificate Problems

Do you have a client that refuses to finish the install of the SCCM client because the certificate doesn't have a private key?

There are 2 different solutions. The easiest is to check the cert store under personnal and see if there are any invalid certs. Delete and restart. The other is a more dangerous solution but will correct the problem

I only recommend this solution if you see all the of the following problems:
CCM Setup Log:
Client sucessfully installed
Applicationn Event Log:

Automatic certificate enrollment for local system failed to enroll for one Computer
certificate (0x80090016). Keyset does not exist

ClientIDManagerStartup:
Certificate issued to 'computer.domain.com' doesn't have private key.
RegTask: Failed to get certificate. Error: 0x80040280
RegTask: Failed to get certificate. Error: 0x80040281
Error initializing client registration (0x80040222).


Solution:
Stop the Crypto Service
Rename the folders under the Crypto Folder
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto

Restart the machine and watch the ClientIDManagerStartup log

See this other post on Certification issues
http://sms-hints-tricks.blogspot.com/2009/03/native-machine-will-not-pull-down.html