SCCM 2012 - Automatic User Device affinity - Not Working

Hi,
I need to enable the Automatic User Device affinity.
Have enabled following two group policy settings:
Audit account logon events
Audit logon events
In client settings User and Device Affinity
following is enabled:
User device affinity threshold (120 minutes)
User device affinity threshold (2 days)
Automatically configure user device affinity from usage data – True
However even after 2 days there is no user device relationship getting build.
Is there anything more required to be done?
Any logs or links to be referred for troubleshooting?
Regards,
Milind Dhuri.

Hi,
Please post this in SCCM 2012 forum.
tx.

Similar Messages

  • Automatic User Device Affinity doesn't work

    Hi, the automatic User Device Affinity doesn't work in my environment and I don't know why! The audit policies are enabled by GPO and User Device Affinity is correctly configured in SCCM. Below are some screenshots including de log of User Device Affinity.
    Anybody could help-me please?

    An old post but,
    This can happened when activating
    advanced audit policy in one of the GPO. once it was activated, it gets override the regular audit policy with different event id's that SCCM don't recognize. in addition, the machine tattooed with those settings so removing the GPO wont revert the settings.
    Check out this thread for more information and help:
    http://social.technet.microsoft.com/Forums/en-US/f3a4b675-e955-4cd2-bba6-d51ea06dd362/user-affinity-not-working-properly?forum=configmanagergeneral
    Please take a moment to Vote as Helpful and/or Mark as Answer where applicable. Thanks.

  • Automatic User device affinity, historical time stamp

    Hi all,
    I have a small questions. I've enabled Automatic User Device Affinity for all my works stations today. After a few hours I've see that nobody has primary device attached. If I go to an user at edit primary device I can see on what devices and how many
    times the user was logged,
    I've setup affinity for minutes 2880 min (48 hours) and 30 days, so who was logged more than 48 hours in last 30 days is made automatically device owner. How long I need to wait now. He can use historical data, no?
    Thanks. 

    No, I dont believe it will use historical data. After 48 hours from you enabling it, you should start seeing primary users, but only if the users have been logged in for 48 consecutive hours.
    Honestly I would not expect data for a good week.
    Daniel Ratliff | http://www.PotentEngineer.com
    I shrink the period 300 min with 14 days. Just to see some reports, after I will come back with longer times. Thanks.

  • Automatic User Device Affinity - Audit logs retention

    Hello,
    We have problems on generating primary user info on a lot Computers and we suspect that problem is because audit logs are kept for too short time.
    So the config is following:
    1) User device affinity threshold (minutes): 2880
    2) User device affinity threshold (days): 30
    So there are two questions:
    1) For how long do we need to keep audit logs on SCCM client to successfully generate user device affinity;
    2) How long do we need to wait till information populates in SCCM DB?
    Thanks,
    Pēteris

    Also from UserAffinity.log I can see that information is sent with state messages:
    "Found same state message existing. (was sent before) Skip sending same state message for user"
    Hi,
    You could try to delete state message about the user in WMI on a client to see if user device affinity could be populated. That is stored in root\ccm\statemsg -> Enum Classes -> Recursive -> double-click CCM_StateMsg -> Instances. There
    should be messages that contain "domain/user_Auto".
    Best Regards,
    Joyce
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • SCCM 2012 Primary Site Recovery - Packages not working

    I recently had to recover my Primary Site due to system crashes with blue screens on a daily basis. I was running ConfigMgr 2012 SP CU 3 and as part of the process I migrated from WS2008 R2 to WS2012 R2.
    After many hours of perusing the web, I found the solutions to deal with the common site recovery issues such as SSL certs, and the content validation due to an empty ContentLib folder. I also had the issue with the update source where it listed the old
    WSUS 3.2 server and the new one so the Site GUID was also updated.
    The issue I am currently experiencing is that packages new or old including software update packages are not working. When using the script by Peter VanWoulde it lists the Deployment State as Error. I have tried redistributing them, valdiating the content,
    removing distribution points, adding in new distribution points and even recreating some of the smaller packages to test but nothing is working.
    Application deployments are working without issues.
    This is the tail end of the WindowsUpdate.log file
    2013-11-20 22:03:27:281 1632 a84 COMAPI >>--  RESUMED  -- COMAPI: Search [ClientId = CcmExec]
    2013-11-20 22:03:28:098 1632 a84 COMAPI   - Updates found = 176
    2013-11-20 22:03:28:098 1632 a84 COMAPI ---------
    2013-11-20 22:03:28:098 1632 a84 COMAPI --  END  --  COMAPI: Search [ClientId = CcmExec]
    2013-11-20 22:03:28:098 1632 a84 COMAPI -------------
    2013-11-20 22:03:32:139 1020 980 Report CWERReporter finishing event handling. (00000000)
    This is the UpdatesDeployment.log file
    Assignment {FD1118D2-563C-44D4-99DB-0CBE29C5C01A} has total CI = 432 UpdatesDeploymentAgent 21/11/2013 8:31:14 AM 4572 (0x11DC)
    Deadline received for assignment ({FD1118D2-563C-44D4-99DB-0CBE29C5C01A}) UpdatesDeploymentAgent 21/11/2013 8:31:14 AM 4572 (0x11DC)
    Detection job ({F5229872-7A7E-4692-B709-63989F708AF0}) started for assignment ({FD1118D2-563C-44D4-99DB-0CBE29C5C01A}) UpdatesDeploymentAgent 21/11/2013 8:31:14 AM 4572 (0x11DC)
    Progress received for assignment ({FD1118D2-563C-44D4-99DB-0CBE29C5C01A}) UpdatesDeploymentAgent 21/11/2013 8:31:26 AM 4572 (0x11DC)
    EnumerateUpdates for action (UpdateActionInstall) - Total actionable updates = 0 UpdatesDeploymentAgent 21/11/2013 8:47:50 AM 3588 (0x0E04)
    EnumerateUpdates for action (UpdateActionInstall) - Total actionable updates = 0 UpdatesDeploymentAgent 21/11/2013 8:47:51 AM 3588 (0x0E04)
    EnumerateUpdates for action (UpdateActionInstall) - Total actionable updates = 0 UpdatesDeploymentAgent 21/11/2013 8:47:55 AM 3588 (0x0E04)
    EnumerateUpdates for action (UpdateActionInstall) - Total actionable updates = 0 UpdatesDeploymentAgent 21/11/2013 8:47:55 AM 2908 (0x0B5C)
    At this point I am running out of ideas of where to look.

    Hi Xin,
    Sorry for not responding earlier but I did recover the site using the guidelines in the following article Backup and Recovery in Configuration Manager,
    however there were a few issues. 
    I did not have a ContentLib backup so all the content had to be redistributed and validated before that worked. None of my packages new or old would work. I eventually found an article from a forum member who also initiated a Site Reset as part of their
    recovery process and had no issues.
    So it seems that any packages are still not working and i think I narrowed it down.
    For some reason even though my DP and MP are all set for HTTPS, it is trying to access the HTTP path for SMS_DP_SMSPKG$. I am using PKI certs so this is the correct path but it should be HTTPS.
    Excerpt from log.
    Retrying DoUpdateSourceListAll task SrcUpdateMgr 09/12/2013 2:26:51 PM 3140 (0x0C44)
    Product {16A45552-A143-4EE6-8CA4-8D95FB5EEB7E} is installed for user  SrcUpdateMgr 09/12/2013 2:26:51 PM 3140 (0x0C44)
    Adding 2 local DPs and 0 remote DPs for product {16A45552-A143-4EE6-8CA4-8D95FB5EEB7E} SrcUpdateMgr 09/12/2013 2:26:51 PM 3140 (0x0C44)
    Adding install source C:\Windows\ccmcache\5l\ to source list for product {16A45552-A143-4EE6-8CA4-8D95FB5EEB7E} SrcUpdateMgr 09/12/2013 2:26:51 PM 3140 (0x0C44)
    UpdateURLWithTransportSettings(): OLD URL - http://xxxxx.com/sms_dp_smspkg$/p01000ae SrcUpdateMgr 09/12/2013 2:26:51 PM 3140 (0x0C44)
    UpdateURLWithTransportSettings(): HTTP requested but client settings prohibit it. SrcUpdateMgr 09/12/2013 2:26:51 PM 3140 (0x0C44)
    Failed source list update for product {16A45552-A143-4EE6-8CA4-8D95FB5EEB7E}, error 87d00226 SrcUpdateMgr 09/12/2013 2:26:51 PM 3140 (0x0C44)
    DoUpdateSourceListAll task failed, error code 87d00226 SrcUpdateMgr 09/12/2013 2:26:51 PM 3140 (0x0C44)
    Source list update task failed, will be retried after 3600 seconds SrcUpdateMgr 09/12/2013 2:26:51 PM 3140 (0x0C44)
    MSI update source list task finished successfully SrcUpdateMgr 09/12/2013 2:26:51 PM 3140 (0x0C44)

  • SCCM 2012 R2 - fresh install PXE not working

    Hi there.
    Fresh install.
    Booting from PXE returns an error: Configuration Manager is looking for policy :(
    Done a lot of googlin so far, nothing helps.
    SMSPXELOGS:
    00:50:56:A8:31:3A, 8D662842-2689-4683-6652-2C8F574F7B8A: No boot action. Rejected.
    00:50:56:A8:31:3A, 8D662842-2689-4683-6652-2C8F574F7B8A: Not serviced.
    Client lookup reply: <ClientIDReply><Identification Unknown="0" ItemKey="0" ServerName=""><Machine><ClientID/><NetbiosName/></Machine></Identification></ClientIDReply>
    00:50:56:A8:31:3A, 8D662842-2689-4683-6652-2C8F574F7B8A: device is not in the database.
    Getting boot action for unknown machine: item key: 2046820353
    Client boot action reply: <ClientIDReply><Identification Unknown="0" ItemKey="2046820353" ServerName=""><Machine><ClientID/><NetbiosName/></Machine></Identification><PXEBootAction
    LastPXEAdvertisementID="" LastPXEAdvertisementTime="" OfferID="" OfferIDTime="" PkgID="" PackageVersion="" PackagePath="" BootImageID="" Mandatory=""/></ClientIDReply>
    00:50:56:A8:31:3A, 8D662842-2689-4683-6652-2C8F574F7B8A: no advertisements found
    bostjanc

    00:50:56:A8:31:3A, 8D662842-2689-4683-6652-2C8F574F7B8A: no advertisements found
    This is an Unknown computer but no advertisements have been found. Have you deployed a task sequence to Unknown Computers?
    Gerry Hampson | Blog:
    www.gerryhampsoncm.blogspot.ie | LinkedIn:
    Gerry Hampson | Twitter:
    @gerryhampson

  • SCCM 2012 - Hardware Inventory Registry Import not working - Windows in the name of the Registry key

    I downloaded the Reg to MOF tool and compiled some of our custom Registry Keys which worked fine. There was particular Key that didn't work and after some testing and messing around I realized why it isn't working:
    The key I am using is: HKLM\Software\MyCompanyWindows
    Because the key has the name Windows in it, it fails to import. I get the generic check the formatting for your MOF file error.
    The MOF file you tried to import could not be compiled. Ensure that the MOF file contains valid data. You can use the command line mofcomp utility to test the data.
    But if I run a MOFCOMP against the MOF I am trying to import it checks the syntax successfully.
    If I change the key to MyCompanyWin or MyCompanyW it imports with no problem.
    We have rolled out this key to almost every device in our organization and connected it to other inventory agents so there is no possibility of changing the key.
    Is there any way to disable the validation check that SCCM is performing?

    Hi,
    If possible, could you please upload the MOF file to SkyDrive?
    Best Regards,
    Joyce Li
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • SCCM 2012 User Device Affinity : Insure affinity is not lost...opinions?

    ok, so i'd like your opinions.  
    situation: i manage a school district environment of around 1500 computers, which is a good mix of labs/student laptops/teacher computers.  
    What I've done is set user device affinity by user to 60 minutes over 7 days.  For helpdesk reasons, we obviously need to be able to bring up the teacher's primary computer through searching for that user's primary device (we use right click tools,
    which is AMAZING...shout-out.)  What happens is when we go on Thanksgiving/Christmas/Summer break, the teacher's are gone for 7/14/90 days respectively.  
    I do not want these user's to lose connection to their primary device, because when we just came back from our 2 week break we find NO connections using right click tools.  
    What I just did was set the days to 90, since 3 months is the longest we'll be away...is that a bad idea, or is there a better way to get this connection to stick?
    Also, if there is a better way to do this, please let me know...i'm open to suggestions. 
    Thank you!  

    Due to our environment I have ours set to 80 hours in 30 days. I have checked machines that haven't reported in since before December of last year and those objects still have the appropriate user defined as the Primary User.
    The thresholds don't define how long the data is held in the database for. It just means "If a user uses a device for x amount of minutes within the window of x amount of days then this device can be considered to be their device." What "X" should equal
    is the variable that you have to make fit your environment. We had to increase the threshold here because techs and other users were getting pulled into too many devices due to their prolonged use of the machine.
    As for why your devices lose their Primary Users, did you configure some sort of custom settings in the site maintenance tasks?
    Dustin Estes - MCP | www.dustinestes.com

  • User device affinity in Microsoft System Center 2012 Configuration Manager

    What would be the microsoft recommended User device affinity  time in sccm 2012
    User device affinity usage threshold (minutes)-?
    User device affinity usage threshold (Days)-?
    Thanks,
    Sengottuvel m

    The default settings seem to work well.
    Gerry Hampson | Blog:
    www.gerryhampsoncm.blogspot.ie | LinkedIn:
    Gerry Hampson | Twitter:
    @gerryhampson

  • How to determine best User Device Affinity Settings

    We've configured User Device Affinity for our site based on the canned defaults. Initially we started with 14 days and 1440 minutes. But after a recent deployment, we discovered that our Antivirus service account is registering as a "Primary User"
    on all of our machines which has triggered a very bad situation.
    My question is how do you determine these settings? My first try was to find a report that showed how many minutes each user was registering in the given period so that I could adjust it accordingly. I assume that my regular users are using the computers
    a lot more than my service account but I have no way of verifying this.
    I've tried combing through the security logs, but I'm not sure what SCCM is picking up on to determine the time period.
    To me, it seems that 24 hours is a really low threshold and that I could bump that up to 120 hours over 14 days pretty easily without issue. My concern is that there is a reason that they are setting it so low to begin with that I'm missing. Even then, I'm
    just randomly trying things hoping to get it right as I don't have the proper information to make the right decisions.
    Any ideas? Feedback?  

    Yeah, I saw those logs but it still seems mysterious to me. I'm not sure where it's getting it's info. I assume it's the security log for each machine but I have nothing to confirm that. It's odd because our service account for our antivirus solution isn't
    actually logging onto the machines so I'm not sure how it decides that this user is a primary user. 
    Ultimately, we worked around the problem by switching antivirus solutions but that won't be an option next time. 
    My guess is that we could have fixed our problem by adjusting our security logging settings in windows. But it wasn't something I wanted to do without direct confirmation with how this all works. 
    Thank you for your help on this though. 

  • User Device Affinity PXE Setting

    In the settings for PXE on a DP, there is an option for user device affinity with three possible choices.  Do not use UDA, use UDA with manual approval or use UDA with automatic approval.  What exactly do these settings do?  The TechNet info
    is a bit vague.
    Select Do not use user device affinity to not associated users with the destination computer.
    Select Allow user device affinity with manual approval to wait for approval from an administrative user before users are associated with the destination computer.
    Select Allow user device affinity with automatic approval to automatically associate users with the destination computer without waiting for approval.
    If I select do not use user device affinity, does that mean that the machine will not participate in UDA regardless of client settings?

    Perhaps this blog post will share some light on what the settings are used for:
    http://blogs.technet.com/b/inside_osd/archive/2011/06/20/configuration-manager-2012-user-device-affinity-and-os-deployment.aspx
    Regards,
    Nickolaj Andersen | www.scconfigmgr.com | @Nickolaja

  • [Forum FAQ]How to troubleshoot common issue when configuring user device affinity from usage data

    Symptom:
    Some clients might fail to automatically configure user device affinity from usage data if you have manually configured user device affinity before.
    When you check the UserAffinity.log, you can find the similar error messages as below:
    User 'XXXXX\XXXXX' has xxxxx usage minutes UserAffinity 
    Setting auto affinity for user 'XXXXX\XXXXX'. UserAffinity 
    Found same state message existing. (was sent before) Skip sending same state message for user 'XXXXX\XXXXX'.. UserAffinity 
    Figure 1. Error Message in UserAffinity.log
    Cause:
    As the log said, there is a user affinity state message existing in WMI which prevents client from sending new user affinity state message.
    Resolution:
    We can delete the user affinity state message in WMI to force the client to resend the user affinity state message.
    We can follow the steps below:
      1. Run Windows Management Instrumentation Tester (“Wbemtest”).
      2. In Windows Management Instrumentation Tester dialog box, click “Connect”.(Figure 2)
    Figure 2.
      3. Type “root\ccm\statemsg” under the Namespace table and then click “Connect”.(Figure 3)
    Figure 3.
      4. Click “Enum Classes”. (Figure 4)
    Figure 4.
      5. Choose “Recursive”
    in Superclass Info dialog box.(Figure 5)
    Figure 5.
      6. Double-click “CCM_StateMsg” in Query Result dialog box.(Figure 6)
    Figure 6.
      7. Click “Instances”
    in Object editor for CCM_StateMsg dialog box. (Figure 7)
    Figure 7.
      8. Choose the messages that contain "domain/user_Auto" and click “Delete” in the Query Result dialog box.(Figure 8)
    Figure 8.
    After you delete user affinity state message in WMI, the user affinity state message for the user will be resent. After a period time, we can check the UserAffinity.log to
    see if the user affinity state message has been successfully sent. The related information would be similar as below:
    Successfully sent user affinity state message for user 'xxxxx\xxxxx'.
    Successfully created pending user affinity for user 'xxxxx\xxxxx' into WMI.
    Figure 9.
    Please click to vote if the post helps you. This can be beneficial to other community members reading the thread.

    I'm not sure whether this is the appropriate place to add this but - a (possible) cause that I have seen which is not mentioned above is a request for an AAAA record (IPv6 address)
    being responded to with an A record (IPv4 address).
    DNS debug logging (Windows 2008 R2 SP1) captured requests to
    192.225.156.200 and the corresponding responses. In each case the response was followed in the debug log by the event “The DNS server encountered an invalid domain name
    in a packet from 192.225.156.200. The packet will be rejected. The event data contains the DNS packet.”
    The domain name in the response was the same as that in the query, and looks OK.
    The logged query shows an AAAA record (IPv6 address) request and the logged response returned an A record (IPv4 address).
    http://www.rfc-editor.org/rfc/rfc4074.txt “Common
    Misbehavior Against DNS Queries for IPv6 Addresses” says, under “Expected Behavior”:
       Suppose that an authoritative server has an A RR but has no AAAA RR
       for a host name.  Then, the server should return a response to a
       query for an AAAA RR of the name with the response code (RCODE) being
       0 (indicating no error) and with an empty answer section (see
       Sections 4.3.2 and 6.2.4 of [1]).  Such a response indicates that
       there is at least one RR of a different type than AAAA for the
       queried name, and the stub resolver can then look for A RRs.

  • User device affinity question

    hi there,
    I have a question around user device affinity with regards to users that have multiple devices due the usage of those machines.
    in most of our cases, users have 1 machine so any targeting of software with the requirement of user being primary user works fine, but we have a number of cases, mainly IT guys and engineers, who run up multiple machines constantly and therefore have
    many "primary" devices, although 1 will probably be their main computer.  If I targeted those users with an uninstall program for, let say Visio, and lets say visio was indeed installed on all of a particular users computers, then, as all those
    computers are regarded as primary device for that user, all visio installs will be removed from all computers.  there is no way to differentiate that I only want visio uninstalled from a users "main" primary device.  ie. it is a case
    of all or nothing.  is that correct, and if so, would it then be a better bet in these cases to uninstall using a computer based method rather then user based, or an SCCM technician would need to make sure that device affinity was cleaned up prior to
    any uninstall deployment?
    I can see how device affinity works nicely where users work as they are supposed to, ie with 1 device. but it is the groups that don't fit into this pattern that I'm trying to get my head around how to manage when deploying apps to users rather than the
    old method of packages to computers.
    also, as an aside, I assume that the uninstall program set up in a deployment type, runs the requirement tests before running in the same way that if you where running the install program it tests?
    thanks
    douglas

    To specify a primary device, you would need to set the User Device Affinity threshold.  By default, it is 2880 minutes over 30 days.  Then, when you create your Deployment Type, you would use the Requirements tab to set Primary Device = True. 
    This way, it will only run on the primary device that was determined by that setting.
    And yes, the Detection Method runs for uninstalls the same way as it does installs. 
    Mike Leach | http://blogs.catapultsystems.com/mleach/default.aspx

  • Keyboard & Trackpad only work before booting, USB devices also not working

    Hi,
    Yesterday I installed MacFuse and NTFS-3G because I needed to store some things on an external drive for work. I rebooted as was instructed in the install docs and that's when things got ugly.
    When on the login screen I've got no keyboard or mouse. Hooking up an external keyboard and mouse didn't work either, they didn't seem to be powered from the USB ports.
    Odd thing is: I can boot to safe mode or single user mode, but after letting it boot I lose keyboard again.
    Things I've tried:
    - Safe mode: keyb not working at logon screen
    - Single user mode: keyb not working at prompt
    - Zapping PRAM: Can zap PRAM, but keyb not working at logon screen
    - Resetting SMC: keyb not working at logon screen
    So at first I thought this was a hardware issue (since USB devices don't get power), but since the keys work when booting up I start to wonder if it's just a software issue.
    Any thoughts on this?
    EDIT: I now hooked on a mouse befor being at the login screen and it seems to get power right up until the apple logo appears (until OSX is booting I presume?). So definitely a software issue? I'll try the setup disc this evening, but I don't want to lose any data. What's the best way to do that?
    Thanks in advance, by the way!
    Message was edited by: Kiff

    Hi,
    Same problem here after a reboot on evening of the 12th, i can boot into hardware test and no problems found, trackpad, keyboard and external USB working ok but when I boot normally, none of the above work.
    I'm fairly new to MacOS but could boot as an firewire drive OK to get files off the machine?
    Anyone have any starting points re drivers or prefers, I've done the PRAM, SMC reset etc, with no difference.
    Thanks
    Carlo

  • Thinking I may have broke User/Device Affinity in my setup?

    Morning,
    User/Device affinity has been working well for us for a number of weeks now.  I think maybe some recent changes I made to Group Policy regarding event logs may have borked it because the number of affinity's is slowing going down over the past
    few days according to the "Use device affinity associations per collection" report. 
    Here are the settings I am currently been using for weeks now:
    User Device Minutes: 960
    User Device days: 7
    Auto config: Yes
    Group Policy stuff:
    Audit account logon events: Success, Failure
    Audit logon events: Success, Failure
    Maximum Security log size: 1048576
    Retain security log: 14 days
    Retention method for security log: by days
    These changes were made just recently which we be the problem.  We made these changes because they were filling up the logs with noise and rolling over:
    Audit Filtering Platform Policy Change: Success
    Audit non sensitive Privilege Use: Success
    Audit Sensitive Privilege Use: Success

    Since no one has answer this post, I recommend opening  a support case with CSS as they can work with you to solve this problem.
    Garth Jones | My blogs: Enhansoft and
    Old Blog site | Twitter:
    @GarthMJ

Maybe you are looking for

  • How to load old voice memos to new iphone 4s

    hello, i'm trying to load old voice memos from 3gs to new 4s. when i plug in the new 4s i have a playlist called voice memos and it appears to be on the 4s  phone but i can't find it on the phone when doing a search for the name and or looking in the

  • How to not  use a credit card for my apple id

    how to not  use a credit card for my apple id

  • List Box in ITS template and use of 'FIELD_SET'

    Hello EveryOne, I am working in SRM5.0. Can some one guide me, If we can create a List box in custom ITS template. I am trying to use SELECT statement on HTML to create LIst Box. Is this right way to do that? Does any one know better way to create a

  • Satellite A200 - Display driver stopped responding

    Periodically I see this warning: [http://s001.radikal.ru/i193/1002/2b/ee6a610aa864.jpg] It appears after short blackout by no reason. What is it? Satellite A200-1CR / Windows 7 Professional

  • Powering on a new Quad G5 ?

    I just got in a Quad, and the reality of not being able to power it on by touching the power button on my ADC monitors, just hit home. I of course have to use the ADC to DVI adapters, and my G5 is located deep under my desk. I have a bad neck, and re