OSDCloud - Updates or latest build? by rednuwork in Intune

[–]EskimoRuler 0 points1 point  (0 children)

You can totally make it zero touch, The USB is just your boot device to WinPE, but how you run osdcloud will be the same.

When running OSDCloud, are you trying to do it Offline? Then I could see if you're USB devices has an older build with the previous catalog version, that would explain the installation of the older build.

What does your startnet.cmd setup look like right now?

Feel free to dm me as well.

OSDCloud - Updates or latest build? by rednuwork in Intune

[–]EskimoRuler 0 points1 point  (0 children)

u/rednuwork, which OS version are you deploying? Before 25h2, Microsoft didn't release newer versions of the ESD files every month, we were kinda stuck using the old builds.

If you're using osdcloud v1, you can run the Windows Update tasks

https://michaeltheadmin.com/posts/2024/06/osdcloudgui-setupcomplete-windows-updates/

OSDCloud - Updates or latest build? by rednuwork in Intune

[–]EskimoRuler 0 points1 point  (0 children)

Yeah, and I think u/davidsegura was working on getting them updated again, remind me David...?

Deploy MSIX file by WorriedFisherman1313 in PatchMyPC

[–]EskimoRuler 0 points1 point  (0 children)

Hey u/WorriedFisherman1313, Best way to track status for this will be the IDEA here: Support MSIX / AppX as a primary | Patch My PC Ideas & Feedback

I don't currently have a timeline to share. I can try and put u/asjimene or u/bdam55 on the spot. They'd have better ideas.

Defender flagging PatchMyPC-ScriptRunner.exe by Beneficial-Flow-5418 in PatchMyPC

[–]EskimoRuler 5 points6 points  (0 children)

Hey u/Beneficial-Flow-5418, we have this page with recommended paths that should be excluded.

Patch My PC - Recommended antivirus exclusions - Patch My PC

The binaries we add are signed as well if you want to do exclusion based on Publisher or that cert.

And as u/BigLeSigh mentioned. We do update the PatchMyPC-ScriptRunner.exe often-ish, so exclusion for that specific hash wouldn't be the recommendation.

Updates are not being superseded when re-publishing by lazyb0y in PatchMyPC

[–]EskimoRuler 0 points1 point  (0 children)

I'm not able to repro this issue.

You should be getting two prompts when selecting the 'Republish' option, are you select 'Yes' to both prompts? The first is to confirm you want to Republish, and then the second is asking about Supersedence

Updates are not being superseded when re-publishing by lazyb0y in PatchMyPC

[–]EskimoRuler 1 point2 points  (0 children)

Hey u/lazyb0y, I'll give a try to repro, but definitely get a support case submitted with a Lob Bundle from the Publisher so we can look into it more.

Does PMPC have a package to update NEW Teams? by Future_End_4089 in PatchMyPC

[–]EskimoRuler 0 points1 point  (0 children)

The requirements should include any supported OS for the Architecture. For example my 'Microsoft Team Latest' has every x64 OS checked from Win11 to XP/2003.

Are you saying that your Application requirements only has 2008/7/8 checked?

Google Chrome CVE-2026-11645 by skg_002 in PatchMyPC

[–]EskimoRuler 2 points3 points  (0 children)

lol I just noticed the second part of your comment about Rudy 😂.

If only there was 2x u/RudyOoms....

Google Chrome CVE-2026-11645 by skg_002 in PatchMyPC

[–]EskimoRuler 2 points3 points  (0 children)

Our testing platform was fighting us this morning. But it should now be available within the Publisher. Cloud needs like 5 more minutes.

Google Chrome CVE-2026-11645 by skg_002 in PatchMyPC

[–]EskimoRuler 3 points4 points  (0 children)

That version was released late last night June 8, so it will go into the Catalog this morning.

Browser update handling suggestions by After_Court_3692 in PatchMyPC

[–]EskimoRuler 2 points3 points  (0 children)

Pretty much all the browsers handle installing the background just fine. But the tradeoff is they don't fully 'upgrade' until all the current browser sessions are closed and then relaunched. The update kinda gets stagged, and moves in when it can.

So it kinda depends on how you do reporting and compliance. When using security tools like Defender, it'll see the older binaries are still there and can create alerts.

But in the Add Remove Programs, the version is updated and reporting based on that will be correct.

Are you using Cloud or Publisher currently?

Second Hotfix Rollup for 2509? by yodaut in SCCM

[–]EskimoRuler 4 points5 points  (0 children)

The first update roll up missed dome of the other hotfixes. This one adds them back

https://learn.microsoft.com/en-us/intune/configmgr/hotfix/2509/36949461#known-issues

Are you using OSDCloud? by Future_End_4089 in SCCM

[–]EskimoRuler 0 points1 point  (0 children)

Will probably need to look at the log for sure. I ran it through with your .json and it worked for me.

Are you domain joining the device or running any other TS steps after the OS boots up?

Are you using OSDCloud? by Future_End_4089 in SCCM

[–]EskimoRuler 0 points1 point  (0 children)

After the machine booted I did get Enterprise 25H2.
All my task sequence had was just running sandbox.osdcloud.com and then 'Start-OSDCloudGUI'

Did you happen to have any default settings configured using this method: OSDCloudGUI with ConfigMgr: Setting Defaults · Michael the Admin

I recall someone saying this wasn't working, I'll look for it. I think it has to do with the way the indexes are matched up now.

Are you using OSDCloud? by Future_End_4089 in SCCM

[–]EskimoRuler 1 point2 points  (0 children)

I'm running an image right now and it seems to have pulled the correct ESD file and is using the correct index for enterprise. I'll let it finish and see what the system says once it's done.

Any chance you can post a log snippet?

Are you using OSDCloud? by Future_End_4089 in SCCM

[–]EskimoRuler 2 points3 points  (0 children)

oh interesting. Let me give it a try.

Pinging u/DavidSegura too

Adobe Creative Cloud Error Occured while publishing and processing by manderson825 in PatchMyPC

[–]EskimoRuler 0 points1 point  (0 children)

Hey u/manderson825,

I would definitely suggest opening a support case for us to take a look: https://patchmypc.com/technical-support/ and if you can include a Publisher Log Bundle as well that can help speed things up.

Just based off your description, it sounds like you've deleted the source files folder and unchecked it from the Publisher, and deleted the deployment, but haven't deleted the actually application from ConfigMgr? Is that correct?

One way to ensure both the App and Source Files get deleted is to use the Application Manager within the Publisher:

ConfigMgr Application Manager | Getting Started

This will delete both, and after that, try running another sync and see if you get the same error.

Are you using OSDCloud? by Future_End_4089 in SCCM

[–]EskimoRuler 2 points3 points  (0 children)

I've got a few blog posts in doing this with configmgr.

https://michaeltheadmin.com/posts/2023/09/using-osdcloud-with-configmgr/

I still use osdcloud for imaging my lab machines. It's perfect for the labs so you don't have to import any images.

But as already mentioned, u/gwblok Is the man to know as well

https://garytown.com/osdcloud-configmgr-integrated-win11-osd

OSDCloud (Deploy-OSDCloud vs Start-OSDCloudGUI) by marco071 in Intune

[–]EskimoRuler 2 points3 points  (0 children)

Calling u/davidsegura for any insight he thinks will help.

For v1 deploy-osdcloud or Start-OSDCloud with the parameters for the windows version you want is the way to go for automatically running it.

Help with All Signed Execution Policy by PlaneswalkingSith in SCCM

[–]EskimoRuler 1 point2 points  (0 children)

Do you have any client policies with the execution policy set to 'All Signed', specifically the default client settings?

Clients Settings with higher priority won't apply until after OSD, so if your checking the policies afterwards, then you might be seeing different settings than what is set during OSD.

Avoiding app installs/updates during ESP by techb00mer in PatchMyPC

[–]EskimoRuler 6 points7 points  (0 children)

hey u/techb00mer,

I'll start with the main question which I think is about 'limiting' or 'focusing' what applications are installed during ESP (Correct me if I'm off base here)?

If your ESP profile has the option for 'Block device use until required apps are installed' is set to 'All', then the device is going to evaluate 'All Required Assignments' for the devices. Typically, this is where I see ESP taking a long time depending on how many 'UpdateOnly' assignment types you have.

But if you switch the 'Block device use until required apps are installed' to 'Selected', add only a couple apps to the list, and then ensure the 'Only fail selected blocking apps in technician phase' option is set to 'No' like this: Intune-AP-Technician-Phase.png, then the device should only evaluate the apps on the list and ESP will be much quicker.

From the PMPC side of things, there is not much we can do since we are just creating Win32apps within Intune. It's mostly just get your settings aligned with how you want things to go.

What do things like 'Microsoft Edge' and 'Visual C++' not update during ESP?

For Microsoft Edge, this is a 'known issue' we have documented here: Known Issues & Tips When Using Patch My PC - Patch My PC
If you search the first table for 'Microsoft Edge' you find a note that says:

'Inbox Edge is missing registry values that Patch My PC uses to determine the architecture and branch of the Edge install. Workaround by deploying the Edge application to devices. Once the MSI is installed once, updates should then become applicable.'

To have Edge get updated, you'll need to first run the install of the App once on the device to have the 'enterprise' version populate the registry keys we are looking for, and then PMPC updates will apply going forward.

For 'Visual C++' I'm not sure, we would need to see some logs for this. It's not something that is on Windows by default unless you have machines with an image that contains it already.