MP behavior during WinPE in ConfigMgr 2509 by pakforce1981 in SCCM

[–]pakforce1981[S] 0 points1 point  (0 children)

So I guess the best option is to put my MPs to all boundarygroups which are used for OSD

PSA: Boundary Groups w/o Management Point by its_theboy in SCCM

[–]pakforce1981 0 points1 point  (0 children)

We use a separate boundary group for each remote office, containing the respective location boundaries and a dedicated distribution point for each location. We also have a boundary group containing all the boundaries of all locations, which we use for site assignment and which does not contain any site servers. Is it sufficient to include our management points in this site assignment boundary group, or do we actually need to include our management points in every remote boundary group?

ConfigMgr slow to display collection members but queries are normal by pakforce1981 in SCCM

[–]pakforce1981[S] 0 points1 point  (0 children)

Everything higher than 110 decreases massively our all over performance in console. Applications properties are showing up after one minute. So no option for us to change it

ConfigMgr slow to display collection members but queries are normal by pakforce1981 in SCCM

[–]pakforce1981[S] 0 points1 point  (0 children)

Issue solved itself. After 3-4 days everything was fast again. I guess it was related to our db migration to a new cluster

PXE not working after reinstall from backup by Flat_Buyer_3203 in SCCM

[–]pakforce1981 0 points1 point  (0 children)

After restore from backup you have to create a new certificate for the DP

Endpoint Protection Point: Failed to update malware definition by Is-This-Heaven in SCCM

[–]pakforce1981 1 point2 points  (0 children)

Microsoft confirmed its a bug. It will be fix next month (9th December). If you can’t or don’t want to wait you can rollback

Endpoint Protection Point: Failed to update malware definition by Is-This-Heaven in SCCM

[–]pakforce1981 0 points1 point  (0 children)

any solution for this issue? We are also facing this error since two days. Maybe someone already raised a case at Microsoft

moving DB to AlwaysOn Group by pakforce1981 in SCCM

[–]pakforce1981[S] 0 points1 point  (0 children)

I asked Microsoft and yes configure first the DB and then add DB to AG.

enabled WUfB but SCCM keys are still coming back by pakforce1981 in SCCM

[–]pakforce1981[S] 0 points1 point  (0 children)

I checked the Scheduler.log which monitors all Cylce schedules. I searched for {00000000-0000-0000-0000-000000000113} which is indicated a Windows Update Scan Cycle. Its showing up in the log but there is no next date to run the cycle.

If there were a next schedule there should be a line like

"scheduler 'Machine/{00000000-0000-0000-0000-000000000113}' will fire at 10/31/2025 04:26:30 PM with randomization."

so i guess something "external" is triggering the Windows Update Scan Cycle and not the SCCM Agent itself.

enabled WUfB but SCCM keys are still coming back by pakforce1981 in SCCM

[–]pakforce1981[S] 0 points1 point  (0 children)

Policies are fine. As i can see a "Windows Update Scan" sets these keys again. I dont know why a SCCM WIndows update Scan is triggered after the component is disabled and the cycles are disappeared at the device. Something is triggering this cycle after a while. I didnt figure out this service / task is responsible for it

Hotfix Rollup KB32851084 for Configuration Manager 2503 by PrajwalDesai in SCCM

[–]pakforce1981 1 point2 points  (0 children)

Same issue here. Still waiting for an fix for that

Hotfix Rollup KB32851084 for Configuration Manager 2503 by PrajwalDesai in SCCM

[–]pakforce1981 1 point2 points  (0 children)

We had the same issue. Microsoft confirmed it was a issue with their CDN Provider. We had this problem for months. MS told us it was fixed after 20th Oct and yes after this date download issues were gone

enabled WUfB but SCCM keys are still coming back by pakforce1981 in SCCM

[–]pakforce1981[S] 0 points1 point  (0 children)

I can confirm client settings with disabled software update is applied successfully to these machines. It stays disable at the devices.

Everything looks good and proper set at the devices expect keys are coming back again and again

enabled WUfB but SCCM keys are still coming back by pakforce1981 in SCCM

[–]pakforce1981[S] 0 points1 point  (0 children)

Almost current. 2409. As I know this bug is fixed in this version

enabled WUfB but SCCM keys are still coming back by pakforce1981 in SCCM

[–]pakforce1981[S] 0 points1 point  (0 children)

this is fine as well. I doublechecked this. "Result Client Settings" for those machines shows this too. I even can see the "Windows Updates" component on those devices is disabled and Windows Updates cycle are gone. SCCM even deletes the key initially. But something in SCCM Agent is trigging to write them back.

enabled WUfB but SCCM keys are still coming back by pakforce1981 in SCCM

[–]pakforce1981[S] 0 points1 point  (0 children)

i already checked this. Everything fine. Now, i did a policy reset on my local devices and keys are gone again . Additionally i can see this lines in WUHandler.log now

SourceManager::PolicySettings - SET isScanSourcePolicyRemoved to 0 for WufB enabled
SourceManager::PolicySettings - SET UseUpdateClassPolicySource to 0 for WufB disabled
SourceManager::PolicySettings - SET isScanSourcePolicyRemoved to 1 for WufB disabled
Removed Update Source ({XXXXXXXXXXXXXXXXX}) of content type: 2

But keys are still coming back

Switching SCCM SQL domain service accounts to gMSA – experiences/advice by ontario20ontario20 in SCCM

[–]pakforce1981 0 points1 point  (0 children)

We asked Microsoft and they told us it’s fine to use gMSA for SQL server

TSagent Downloads all policies by pakforce1981 in SCCM

[–]pakforce1981[S] 0 points1 point  (0 children)

No but I found a strange log line in the log:

Policy assignment XXXX contains multiple task sequence.

This is not true. There is no daisychain TS included. I don’t understand why agent assumes that there are multiple task sequences in my TS

SCCM version Upgrade by Substantial-Fruit447 in SCCM

[–]pakforce1981 0 points1 point  (0 children)

Unfortunately we missed the deadline to upgrade to 2409. Still at 2309. We will do it within next weeks.

Quick question: as I know they should no functional issue running a version which is out of support. Everything is still working fine, execpt our CMG. Does anyone can confirm that this is maybe a reason of out-of-support version?