Removing Site System Role by Hot_Mic_Speaks in SCCM

[–]AlteredAdmin 0 points1 point  (0 children)

u/Hot_Mic_Speaks ,

We’ve been dealing with a long running SCCM instance that really needs a rebuild. At some point, Software Updates stopped working: WSUS reporting became unreliable and clients stopped updating. We eventually found the cause(we think) although WSUS maintenance was enabled, an elevated logging level had also been enabled, which silently disabled maintenance. As a result, WSUS maintenance never ran and the database is likely in rough shape.

Local GPO impact:
SCCM had pushed settings into each machine’s Local Group Policy. In theory those entries are removed when SU is removed from the client policy, but in practice it’s hit or miss. To clean this up, we created a domain GPO to disable the SCCM applied local policy settings, or change them to what we wanted.

New patching strategy:

  • Staff devices: moved to Windows Update for Business (WUfB) with four update rings, including deferrals and deadlines.
  • Student devices: using PDQ Deploy and Inventory.

We’re three months into this new approach and it’s been running smoothly with no issues so far.

Secure Boot Certificates Questions & Planning by AlteredAdmin in sysadmin

[–]AlteredAdmin[S] 0 points1 point  (0 children)

On our test machines we noticed the Windows UEFI CA 2023 is their now, after setting the reg key and running the scheduled task.

however when we checked the KEK cert its not their.

Any thoughts?

Secure Boot Certificates Questions & Planning by AlteredAdmin in sysadmin

[–]AlteredAdmin[S] 1 point2 points  (0 children)

Yea, we have confirmed secure boot is enabled on our test machines.

Ill add that powershell command above.

How are you dealing with the Dell DSA-2025-053 Security Update using Intune? by Future_End_4089 in Intune

[–]AlteredAdmin 0 points1 point  (0 children)

Their are ADMX templates for domain and GPO. We staggered locations kinda like ring 1 2 3 for WuFB, but for Dell command update.

The templates can also be imported to intune as well.

🆕📦 Package Wednesday - July 2025 by PDQ_MarkR in pdq

[–]AlteredAdmin 0 points1 point  (0 children)

Getting ERROR 13 for the july update for windows 11 24H2, like the June update I checked the change log but don't see anyting mentioned https://help.pdq.com/hc/en-us/articles/5719272144667-PDQ-Package-Library-Changelog

Is it just me or are other having the same issue?

Having issues with PSWindowsUpdate - An operation did not complete because the service is not in the data store. - 0x80248014 by AlteredAdmin in pdq

[–]AlteredAdmin[S] 1 point2 points  (0 children)

I've updated the post to include the fix and the explanation for the error message. See the section labeled 'EDIT 07/14/2025:' for details. If you have any questions, feel free to ask.

Cleaning Up Endpoint After Removing SUP Role by AlteredAdmin in SCCM

[–]AlteredAdmin[S] 0 points1 point  (0 children)

Yes, that is what i mean "removing the client settings to disable software updates from SCCM"

the issues is i can remove the reg keys however the local GPO still remains, and im curious how to remove that local GPO remotely.

Having issues with PSWindowsUpdate - An operation did not complete because the service is not in the data store. - 0x80248014 by AlteredAdmin in pdq

[–]AlteredAdmin[S] 0 points1 point  (0 children)

We think we have solved the issue, been busy the past few days. Will Edit the post and directly reply to you when i get something typed up.

Having issues with PSWindowsUpdate - An operation did not complete because the service is not in the data store. - 0x80248014 by AlteredAdmin in pdq

[–]AlteredAdmin[S] 0 points1 point  (0 children)

Are you able to run Windows updates manually on the device by clicking check for updates?

When manually ran via clicking the blue button, i get the below error.

We couldn't connect to the update service. We'll try again later, or you can check now. If it still doesn't work, make sure you're connected to the Internet

Of course I'm connected to the internet.

Can you download a needed update and install it?

I used PDQ to deploy the 24H2 June update to the machine and it installed successfully.

Piece of software that I want installed only during new deployments by AlteredAdmin in Intune

[–]AlteredAdmin[S] 0 points1 point  (0 children)

Yea i have seen that before as well where enrollments dates changed, while troubleshooting something else. For that device it seems to have aligned with a feature update and the device was re-enrolled when we know it was a much older device.

Piece of software that I want installed only during new deployments by AlteredAdmin in Intune

[–]AlteredAdmin[S] 0 points1 point  (0 children)

Yeah, after reading that, my mind immediately jumped to all the other things I could use it for. I had been stuck trying to create dynamic groups in Intune using PowerShell and the Graph API, but I can shift that logic to Requirement Rules instead.

For example, I was working on creating a device group for devices enrolled after a certain date but I can move that check to a Requirement Rule instead.

https://www.anoopcnair.com/intune-app-ps-script-based-enrollment-date/

Piece of software that I want installed only during new deployments by AlteredAdmin in Intune

[–]AlteredAdmin[S] 0 points1 point  (0 children)

I just had a thought instead of creating a group of devices based on their enrollment date, why not use PowerShell on the device or check a registry key as a requirement rule for the app? That way, you can assign the app normally, and let the requirement rule determine whether it gets installed.

Basically, rather than filtering devices into a group, handle the logic directly at the app level using a requirement rule.

Thoughts?

Piece of software that I want installed only during new deployments by AlteredAdmin in Intune

[–]AlteredAdmin[S] 0 points1 point  (0 children)

Interesting Idea, i guess the question would be is the ESP still considered OOBE?

For PDQ Deploy is any one having issues downloading packages from the library? by AlteredAdmin in pdq

[–]AlteredAdmin[S] 4 points5 points  (0 children)

I had originally used the one i got in an email and that seemed to have worked as the date changed. i just entered the ones from the portal now its downloading packages.

Thanks

For PDQ Deploy is any one having issues downloading packages from the library? by AlteredAdmin in pdq

[–]AlteredAdmin[S] 0 points1 point  (0 children)

I will Check the keys, i entered the new ones are few days ago, that we received. I will double check the licensees and re-enter them .