Change Software Updates deployment priority

Hi
We use SCCM 2012 R2 CU2.
whenever a new client is being installed and registered it gets its policies and deployments.
our problem is that there are many software updates that being deployed and it takes a very long time until they finish their installation.
while what is more important for us is the clients to get software deployments
before the software updates.
I know I can change packages priority but as I understand - it only changes the priority between the software packages.
is there any way to make the software deployments to be installed before the software updates for new clients?
even if there's no build-in solution, I'd be happy to get a friendly workaround.
I thought about auto-adding the clients to a software update deployment collection only after all the packages are being deployed, but maybe some of you can come up with something better
thanks!

You can't prioritize in policy for a client. The first policy that arrives is the first that's being served..
If you're talking about the first thing after the OS deployment, then I would try to update my clients completely during the deployment already. That would solve your problem already. In that same scenario, you could also think about installing
computer or user targetted applications during the task sequence. For examples about both scenario's see:
Computer-targeted:
http://www.petervanderwoude.nl/post/install-computer-targeted-application-during-os-deployment-via-powershell-and-configmgr-2012/;
User-targeted:
http://www.petervanderwoude.nl/post/install-user-targeted-applications-during-os-deployment-via-powershell-and-configmgr-2012/.
If you're not talking about an OS deployment, your only option is indeed to add the clients later to the software update collection(s). In that case you could also try to automate it via PowerShell by using the
Add-CMDeviceCollectionDirectMembershipRule.
My Blog: http://www.petervanderwoude.nl/
Follow me on twitter: pvanderwoude

Similar Messages

  • Windows Update Agent rebooting systems after Software Update deployment

    I have a software update deployment that is configured to install software updates on a collection of servers at 4:00 AM with a suppressed reboot. The updates get deployed and no reboot occurs as expected.  Then ~8 hours later WUA starts up and the
    servers get rebooted.
    There is a maintenance window applied to the collection from 4:00 AM to 6:00 AM to allow the updates to install.
    I've read a few forum and blog posts on this issue and have implemented some settings via GPO, but the reboots are still occurring.  The settings that were applied are referenced in the link below.
    https://support.microsoft.com/kb/2476479?wa=wsignin1.0
    Here is a snippet from the WindowsUpdate.log:
    2014-10-22 12:00:26:153 1428 8a88 AU Received AU Resume timeout
    2014-10-22 12:00:26:153 1428 8a88 AU Additional Service {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782} with Approval type {Pre-install notify} added to AU services list
    2014-10-22 12:00:26:153 1428 8a88 AU Can not perform non-interactive scan if AU is interactive-only
    2014-10-22 12:02:08:512 1428 8a88 AU AU received policy change subscription event
    2014-10-22 12:16:43:463 1428 8a88 AU ###########  AU: Uninitializing Automatic Updates  ###########
    2014-10-22 12:16:43:479 1428 8a88 WuTask Uninit WU Task Manager
    2014-10-22 12:16:43:697 1428 8a88 Service *********
    2014-10-22 12:16:43:697 1428 8a88 Service **  END  **  Service: Service exit [Exit code = 0x240001]
    2014-10-22 12:16:43:697 1428 8a88 Service *************
    2014-10-22 12:19:29:728 1428 e584 Misc ===========  Logging initialized (build: 7.8.9200.16604, tz: -0400)  ===========
    2014-10-22 12:19:29:728 1428 e584 Misc   = Process: C:\WINDOWS\system32\svchost.exe
    2014-10-22 12:19:29:728 1428 e584 Misc   = Module: c:\windows\system32\wuaueng.dll
    2014-10-22 12:19:29:728 1428 e584 Service *************
    2014-10-22 12:19:29:728 1428 e584 Service ** START **  Service: Service startup
    2014-10-22 12:19:29:728 1428 e584 Service *********
    2014-10-22 12:19:29:744 1428 e584 Agent   * WU client version 7.8.9200.16604
    2014-10-22 12:19:29:744 1428 e584 Agent   * Base directory: C:\WINDOWS\SoftwareDistribution
    2014-10-22 12:19:29:744 1428 e584 Agent   * Access type: No proxy
    2014-10-22 12:19:29:744 1428 e584 Service UpdateNetworkState Ipv6, cNetworkInterfaces = 2.
    2014-10-22 12:19:29:744 1428 e584 Service UpdateNetworkState Ipv4, cNetworkInterfaces = 2.
    2014-10-22 12:19:29:744 1428 e584 Agent   * Network state: Connected
    2014-10-22 12:19:29:744 1428 e584 Service UpdateNetworkState Ipv6, cNetworkInterfaces = 2.
    2014-10-22 12:19:29:744 1428 e584 Service UpdateNetworkState Ipv4, cNetworkInterfaces = 2.
    2014-10-22 12:19:29:791 1428 e584 Agent ***********  Agent: Initializing global settings cache  ***********
    2014-10-22 12:19:29:791 1428 e584 Agent   * Endpoint Provider: 00000000-0000-0000-0000-000000000000
    2014-10-22 12:19:29:791 1428 e584 Agent   * WSUS server:
    http://Internal-WSUS.Domain:8530
    2014-10-22 12:19:29:791 1428 e584 Agent   * WSUS status server:
    http://Internal-WSUS.Domain:8530
    2014-10-22 12:19:29:791 1428 e584 Agent   * Target group: (Unassigned Computers)
    2014-10-22 12:19:29:791 1428 e584 Agent   * Windows Update access disabled: No
    2014-10-22 12:19:29:791 1428 e584 Misc WARNING: Network Cost is assumed to be not supported as something failed with trying to get handles to wcmapi.dll
    2014-10-22 12:19:29:806 1428 e584 WuTask WuTaskManager delay initialize completed successfully..
    2014-10-22 12:19:29:822 1428 e584 Report CWERReporter::Init succeeded
    2014-10-22 12:19:29:822 1428 e584 Agent ***********  Agent: Initializing Windows Update Agent  ***********
    2014-10-22 12:19:29:822 1428 e584 DnldMgr Download manager restoring 0 downloads
    2014-10-22 12:19:29:838 1428 e584 AU ###########  AU: Initializing Automatic Updates  ###########
    2014-10-22 12:19:29:838 1428 e584 AU Additional Service {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782} with Approval type {Pre-install notify} added to AU services list
    2014-10-22 12:19:29:838 1428 e584 AU AIR Mode is disabled
    2014-10-22 12:19:29:838 1428 e584 AU   # Policy Driven Provider:
    http://Internal-WSUS.Domain:8530
    2014-10-22 12:19:29:838 1428 e584 AU   # Detection frequency: 22
    2014-10-22 12:19:29:838 1428 e584 AU   # Approval type: Disabled (User preference)
    2014-10-22 12:19:29:838 1428 e584 AU   # Auto-install minor updates: No (User preference)
    2014-10-22 12:19:29:838 1428 e584 AU   # ServiceTypeDefault: Service 117CAB2D-82B1-4B5A-A08C-4D62DBEE7782 Approval type: (Pre-install notify)
    2014-10-22 12:19:29:838 1428 e584 AU   # Will interact with non-admins (Non-admins are elevated (User preference))
    2014-10-22 12:19:29:838 1428 e584 AU WARNING: Failed to get Wu Exemption info from NLM, assuming not exempt, error = 0x80240037
    2014-10-22 12:19:29:853 1428 e584 AU AU finished delayed initialization
    2014-10-22 12:19:29:884 1428 e584 AU #############
    2014-10-22 12:19:29:884 1428 e584 AU ## START ##  AU: Search for updates
    2014-10-22 12:19:29:884 1428 e584 AU #########
    2014-10-22 12:19:29:884 1428 e584 Agent SkipSelfUpdateCheck search flag set for serverId: 117CAB2D-82B1-4B5A-A08C-4D62DBEE7782
    2014-10-22 12:19:30:416 1428 e584 Report ***********  Report: Initializing static reporting data  ***********
    2014-10-22 12:19:30:416 1428 e584 Report   * OS Version = 6.2.9200.0.0.197008
    2014-10-22 12:19:30:416 1428 e584 Report   * OS Product Type = 0x00000008
    2014-10-22 12:19:30:416 1428 e584 Report   * Computer Brand = HP
    2014-10-22 12:19:30:416 1428 e584 Report   * Computer Model = ProLiant BL460c Gen8
    2014-10-22 12:19:30:416 1428 e584 Report   * Platform Role = 1
    2014-10-22 12:19:30:416 1428 e584 Report   * AlwaysOn/AlwaysConnected (AOAC) = 0
    2014-10-22 12:19:30:431 1428 e584 Report   * Bios Revision = I31
    2014-10-22 12:19:30:431 1428 e584 Report   * Bios Name = Default System BIOS
    2014-10-22 12:19:30:431 1428 e584 Report   * Bios Release Date = 2014-02-10T00:00:00
    2014-10-22 12:19:30:431 1428 e584 Report   * Bios Sku Number = 641016-B21     
    2014-10-22 12:19:30:431 1428 e584 Report   * Bios Vendor = HP
    2014-10-22 12:19:30:431 1428 e584 Report   * Bios Family = ProLiant
    2014-10-22 12:19:30:431 1428 e584 Report   * Bios Major Release = 255
    2014-10-22 12:19:30:431 1428 e584 Report   * Bios Minor Release = 255
    2014-10-22 12:19:30:431 1428 e584 Report   * Locale ID = 1033
    2014-10-22 12:19:30:431 1428 e584 AU <<## SUBMITTED ## AU: Search for updates  [CallId = {2787252C-D4B8-46B5-BB42-0C616042113C} ServiceId = {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782}]
    2014-10-22 12:19:30:431 1428 dae0 Agent *************
    2014-10-22 12:19:30:431 1428 dae0 Agent ** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2014-10-22 12:19:30:431 1428 dae0 Agent *********
    2014-10-22 12:19:30:431 1428 dae0 Agent   * Online = No; Ignore download priority = No
    2014-10-22 12:19:30:431 1428 dae0 Agent   * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1
    or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
    2014-10-22 12:19:30:431 1428 dae0 Agent   * ServiceID = {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782} Third party service
    2014-10-22 12:19:30:431 1428 dae0 Agent   * Search Scope = {Machine & All Users}
    2014-10-22 12:19:30:431 1428 dae0 Agent   * Caller SID for Applicability: S-1-5-18
    2014-10-22 12:19:30:494 1428 dae0 Agent   * Found 0 updates and 0 categories in search; evaluated appl. rules of 0 out of 0 deployed entities
    2014-10-22 12:19:30:494 1428 dae0 Agent *********
    2014-10-22 12:19:30:494 1428 dae0 Agent **  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2014-10-22 12:19:30:494 1428 dae0 Agent *************
    2014-10-22 12:19:30:509 1428 d158 AU >>##  RESUMED  ## AU: Search for updates [CallId = {2787252C-D4B8-46B5-BB42-0C616042113C} ServiceId = {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782}]
    2014-10-22 12:19:30:509 1428 d158 AU   # 0 updates detected
    2014-10-22 12:19:30:509 1428 d158 AU #########
    2014-10-22 12:19:30:509 1428 d158 AU ##  END  ##  AU: Search for updates  [CallId = {2787252C-D4B8-46B5-BB42-0C616042113C} ServiceId = {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782}]
    2014-10-22 12:19:30:509 1428 d158 AU #############
    2014-10-22 12:19:30:509 1428 d158 AU All AU searches complete.
    2014-10-22 12:19:30:525 1428 e584 AU #############
    2014-10-22 12:19:30:525 1428 e584 AU ## START ##  AU: Search for updates
    2014-10-22 12:19:30:525 1428 e584 AU #########
    2014-10-22 12:19:30:525 1428 e584 AU Additional Service {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782} with Approval type {Pre-install notify} added to AU services list
    2014-10-22 12:19:30:525 1428 e584 Agent SkipSelfUpdateCheck search flag set for serverId: 117CAB2D-82B1-4B5A-A08C-4D62DBEE7782
    2014-10-22 12:19:30:525 1428 e584 AU <<## SUBMITTED ## AU: Search for updates  [CallId = {A3E41A4C-E9CB-4172-B6B0-99D556FB9102} ServiceId = {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782}]
    2014-10-22 12:19:30:525 1428 dae0 Agent *************
    2014-10-22 12:19:30:525 1428 dae0 Agent ** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2014-10-22 12:19:30:525 1428 dae0 Agent *********
    2014-10-22 12:19:30:525 1428 dae0 Agent   * Online = Yes; Ignore download priority = No
    2014-10-22 12:19:30:525 1428 dae0 Agent   * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1
    or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
    2014-10-22 12:19:30:525 1428 dae0 Agent   * ServiceID = {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782} Third party service
    2014-10-22 12:19:30:525 1428 dae0 Agent   * Search Scope = {Machine & All Users}
    2014-10-22 12:19:30:525 1428 dae0 Agent   * Caller SID for Applicability: S-1-5-18
    2014-10-22 12:19:30:525 1428 dae0 Misc Validating signature for C:\WINDOWS\SoftwareDistribution\WuRedir\9482F4B4-E343-43B6-B170-9A65BC822C77\wuredir.cab:
    2014-10-22 12:19:30:541 1428 dae0 Misc  Microsoft signed: Yes
    2014-10-22 12:19:30:541 1428 dae0 Misc  Infrastructure signed: Yes
    2014-10-22 12:19:30:556 1428 dae0 EP Got 9482F4B4-E343-43B6-B170-9A65BC822C77 redir SecondaryServiceAuth URL: "http://fe2.ws.microsoft.com/w81/2/redir/v2-storeauth.cab"
    2014-10-22 12:19:30:588 1428 dae0 Agent Checking for updated auth cab for service 117cab2d-82b1-4b5a-a08c-4d62dbee7782 at
    http://fe2.ws.microsoft.com/w81/2/redir/v2-storeauth.cab
    2014-10-22 12:19:30:588 1428 dae0 Misc Validating signature for C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\117cab2d-82b1-4b5a-a08c-4d62dbee7782.cab:
    2014-10-22 12:19:30:603 1428 dae0 Misc  Microsoft signed: Yes
    2014-10-22 12:19:30:603 1428 dae0 Misc  Infrastructure signed: Yes
    2014-10-22 12:19:30:775 1428 dae0 Misc Validating signature for C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\117cab2d-82b1-4b5a-a08c-4d62dbee7782.cab:
    2014-10-22 12:19:30:791 1428 dae0 Misc  Microsoft signed: Yes
    2014-10-22 12:19:30:791 1428 dae0 Misc  Infrastructure signed: Yes
    2014-10-22 12:19:30:791 1428 dae0 Misc Validating signature for C:\WINDOWS\SoftwareDistribution\WuRedir\117CAB2D-82B1-4B5A-A08C-4D62DBEE7782\wuredir.cab:
    2014-10-22 12:19:30:806 1428 dae0 Misc  Microsoft signed: Yes
    2014-10-22 12:19:30:806 1428 dae0 Misc  Infrastructure signed: Yes
    2014-10-22 12:19:30:822 1428 dae0 EP Got 117CAB2D-82B1-4B5A-A08C-4D62DBEE7782 redir Client/Server URL: "https://fe2.ws.microsoft.com/v6/ClientWebService/client.asmx"
    2014-10-22 12:19:30:978 1428 dae0 PT +++++++++++  PT: Synchronizing server updates  +++++++++++
    2014-10-22 12:19:30:978 1428 dae0 PT   + ServiceId = {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782}, Server URL =
    https://fe2.ws.microsoft.com/v6/ClientWebService/client.asmx
    2014-10-22 12:19:31:025 1428 dae0 Agent   * Found 0 updates and 0 categories in search; evaluated appl. rules of 0 out of 0 deployed entities
    2014-10-22 12:19:31:025 1428 dae0 Agent *********
    2014-10-22 12:19:31:025 1428 dae0 Agent **  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2014-10-22 12:19:31:025 1428 dae0 Agent *************
    2014-10-22 12:19:31:025 1428 d158 AU >>##  RESUMED  ## AU: Search for updates [CallId = {A3E41A4C-E9CB-4172-B6B0-99D556FB9102} ServiceId = {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782}]
    2014-10-22 12:19:31:025 1428 d158 AU   # 0 updates detected
    2014-10-22 12:19:31:025 1428 d158 AU #########
    2014-10-22 12:19:31:025 1428 d158 AU ##  END  ##  AU: Search for updates  [CallId = {A3E41A4C-E9CB-4172-B6B0-99D556FB9102} ServiceId = {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782}]
    2014-10-22 12:19:31:025 1428 d158 AU #############
    2014-10-22 12:19:31:025 1428 d158 AU All AU searches complete.
    2014-10-22 12:19:31:025 1428 d158 AU AU setting next detection timeout to 2014-10-23 14:19:28
    2014-10-22 12:19:36:025 1428 e214 Report REPORT EVENT: {E04012FD-8FFD-4259-96D5-A5A34127F0A0} 2014-10-22 12:19:31:025-0400 1 147 [AGENT_DETECTION_FINISHED] 101 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Success Software
    Synchronization Windows Update Client successfully detected 0 updates.
    2014-10-22 12:19:36:025 1428 e214 Report CWERReporter finishing event handling. (00000000)
    2014-10-22 12:29:29:914 1428 e584 AU AU invoking RebootSystem (OnRebootNow)
    2014-10-22 12:29:30:055 1428 e584 AU Allowing auto firmware installs at next shutdown
    2014-10-22 12:29:30:102 1428 e584 Misc WARNING: SUS Client is rebooting system.
    2014-10-22 12:29:30:102 1428 e584 AU AU invoking RebootSystem (OnRebootRetry)
    2014-10-22 12:29:30:367 1428 e584 Shutdwn Checking to see whether install at shutdown is appropriate
    2014-10-22 12:29:30:367 1428 e584 Shutdwn user declined update at shutdown
    2014-10-22 12:29:30:367 1428 e584 AU AU initiates service shutdown
    2014-10-22 12:29:30:367 1428 e584 AU ###########  AU: Uninitializing Automatic Updates  ###########
    2014-10-22 12:29:30:399 1428 e584 WuTask Uninit WU Task Manager
    2014-10-22 12:29:30:445 1428 e584 Agent Sending shutdown notification to client
    2014-10-22 12:29:30:445 5788 8084 COMAPI WARNING: Received service shutdown/self-update notification.
    2014-10-22 12:29:30:461 1428 e584 Report CWERReporter finishing event handling. (00000000)
    2014-10-22 12:29:30:539 1428 e584 Service *********
    2014-10-22 12:29:30:539 1428 e584 Service **  END  **  Service: Service exit [Exit code = 0x240001]
    2014-10-22 12:29:30:539 1428 e584 Service *************
    Any assistance is appreciated.
    -Tim

    Hi,
    Any update?
    Best Regards,
    Joyce
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • How to calculate the compliance for an software update deployment

    Hi All,
    I am trying to find as how do we calculate the compliance for an software update deployment.
    Scenario, We have about 4000 machine in the domain. but we have some stale records in the domain which is about 1200. The AD cleanup for the stale records is planned for sometime in March.
    So total number of machines in a collection (including the stale machines) are 5200.
    The current compliance of that deployment shows the following status:
    Complaint : 1156
    In Progress : 1724
    Error : 38
    Unknown : 2462
    And in the unknown, we have :
    Client check failed/Active: 2
    Client check failed/Inactive: 6
    Client check passed/Active: 732
    Client check passed/Inactive: 1722
    Can you please suggest in understanding the formula that should be followed to get the compliance.

    Your Compliancy, should be based solely off of the number of computers within CM12.
     There are no “if”, “and” or “but” able it.  This is the only way to truly and reliably provide numbers to management.
    Again it should be very simple calculation:
     (Total outstanding  Security SU, Total outstanding
     Critical SU, Total outstand Service packs, Total outstand Update Rollups, Total outstand Updates, Total outstand Definition Updates, Total outstand tools, Total outstand Feature packs) Vs Total applied SU (all Classifications)
    Or
    Total # of 100% patched PCs vs Total # of PCs as seen by CM12.
    If you use any other calculation then you MUST include a disclaimer that you are filtering out computers because they might be invalid. Or you MUST define exactly how you are calculating the number. Therefore any compliancy rate that your calculate maybe
    invalid too or at least it will change once you clean up AD.
    I will never hide low compliancy numbers to management, I will always show it to them.
     In many case I will ask to give a presentation to Management to explain why the numbers are so low.
     Provide them with a list of action items that need to be done in order to bring up the number to more reasonable level. I also set their expectation on what a reasonable level is.
    100% is unachievable; there is no exception to this!
    95-99% Very excellent but expect to spend lots of $$$s to obtain these percentages.
    90-95% is really, really, good; expect to spend $$s in this range.
    85-89% is good; expect to set strict procedures
    81-84 is ok but you could do better
    Below 80% is bad
    In your case, I would start by saying AD is dirty and need to be clean up, this has been schedule for March 2015. I would follow up this to say, in order to keep AD clean the follow procedures need to be define / updated / followed. You should also define
    exactly what you are doing to ensure that all computers are management by CM12.
    IMO these is no simple answer of this.
    Garth Jones | My blogs: Enhansoft and
    Old Blog site | Twitter:
    @GarthMJ

  • How to troubleshoot Software Update Deployment Errors

    Hi Guys,
    Could you guys please help me to troubleshoot 'Software Update Deployment Errors'. I have been trying to troubleshoot the below mentioned errors but I am not sure what step should I take for each different errors.
    Could you guys please help me stating what kind of troubleshooting steps should we take for such update deployment errors.
    Many Thanks,
    Chandan

    You would have to examine client-side logs like UpdatesDeployment.log, U*.log in general, ScanAgent.log, WUAHandler.log, WindowsUpdate.log and CI*.log.
    Torsten Meringer | http://www.mssccmfaq.de

  • SCCM - software updates deployment.

    Hi All,
    i have adobe acrobat version 10.1.10 installed on my mahcine, when ever i am trying to up deploy an Adobe acrobat 10.1.13 for my machine using but its not gettin updated. Also , one thing that i have seen is even after deployment it is not showing up under
    deployment package.
    Can anyone help on this, Iam using shavlik higher version of SCUP with SCCM to achieve this.
    Rsg,

    Hi,
    You could troubleshoot software updates deployment by checking logs.
    UpdatesDeployment.log
    UpdatesHandler.log
    WUAHandler.log
    %windir%\WindowsUpdate.log
    For more information:https://technet.microsoft.com/en-us/library/hh427342.aspx#BKMK_SU_NAPLog
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

  • Software Updates Deployment Shows "Unknown" Computers, Previously Had Compliant

    I'm not sure what is going on, but can anyone tell me why a software updates deployment would all of a sudden show all computers as having an "Unknown" status?  Previously, most computers were "Compliant" and there were a couple
    with errors.  When I went to check it (about a week after the original deployment), I found it had reset all to "Unknown" status.  This was yesterday, and now today there are a couple computers showing "Compliant" but most are
    still "Unknown".  It is not set up with ADR, so it's not (at least I don't think) looking for newer updates.  Any ideas?

    A re-evaluation of the software update deployment, which you configure in the client settings, can cause this behavior. That's why you should always use the reports for compliance checks and not the deployments node.
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • Software Updates Deployment Evaluation.

    Hi,
    I would like to get some clarification around the Software Updates Deployment Eval. cycle. (SCCM R2 CU3)
    Example scenario:
    I have a Software Update Group that contains 200 updates. This SUG includes updates that are prerequisites for other updates in the same SUG. So, when scanning occurs. Only one of these updates are at that particular time considered applicable.
    The software update deployment deadline is reached. The update is installed, as expected. The then agent reports  compliance against the update deployment.
    Then comes the Software Update Scan schedule, when a new scan is made against the SUP more updates are now detected as required because of the previously installed update - from the same SUG which are deployed.
    This leaves me in a situation where the agent is compliant against the Software Update deployment and non-compliant in regards to the actual Software Update Group. 
    I can of course just hit the schedule for Software Update Deployment Evaluation manually on the agent or simply do something (adding an update or whatever) that modifies the actual software updates deployment policy. This would in turn cause a new evaluation
    to occur at the client.
    Bottom line. Is my conclusion correct or have i missed something here? 
    If i'm correct, a good thing would be to add scheduling options available for the actual "software update deployment evaluation".
    That would really come in handy in situations like above scenario. 
    Br,
    Chris

    The next scheduled scan cycle will pick up the newly applicable but non-compliant updates in the deployment.
    However, note that update compliance at the client level is done against the entire update catalog as this is actually done by the Windows Update Agent (WUA) which knows nothing about ConfigMgr. Thus, the fact that an update is in a deployment or not is
    completely irrelevant as far as compliance and compliance reporting goes (which is part of the reason why compliance reporting in ConfigMgr is tricky).
    Updating the policy of an update deployment will kick off a scan cycle (just like creating a new deployment will) on the clients which is why you are probably seeing this behavior as addressing the scenario.
    Jason | http://blog.configmgrftw.com | @jasonsandys
    Thanks Jason,
    What you are describing exactly matches the point I’m trying to make here. There is no correlation what so ever between update scans and actual software update deployments. The logic just isn't there. Which is a logic that is lacking
    – in my opinion.
    I really do think there is room for improvement here.
    Case:
    A customer wants to minimize the spread of reboots (a maint. window overnight should be sufficient for the agent to get the server fully up to date). The admin – who also wants to minimize effort in regards to worrying about MS bundling\prereq
    requirements – simply wants it all to be taken care of by the updates deployment agent.
    Example:
    Software update deployment contains required updates as well as updates that will not be detected as required - until the deployment has been run – and a new update scan cycle has taken place.
    The server reboots and updates deployment agent says all is fine – with regards to the deployment in it's current state, of course.
    But it's not.
    The server then issues a new scan (maybe 4 hours later and way behind the end of the maint. window) according to the software updates scan schedule, and suddenly 10 more updates are applicable, but still within the same deployment.
    What happens? Nothing, sadly. Next maint. window? Nothing.
    Not even a (client agent set – and scheduled) software update deployment re-eval takes care of this since – according to my findings – the deployment will never really be evaluated against again without administrative intervention.
    Suggestion:
    Whenever a software update deployment has been run, succeeded and passed the "after reboot" detectjob. Initiate a new evaluation of this deployment in full – of course including a pre-eval software updates scan. Just add
    a few steps to the logic of updates deployment.
    Evaluate.
    Apply.
    Initiate a new scan.
    Re-Evaluate.
    Apply again (if needed)
    Reboot
    Initiate a new scan.
    Re-evaluate
    Isn’t this the way WAUA has always worked? Why shouldn’t this method be adopted here as well? Why should ConfigMgr not honour the procedure?
    Result:
    Administrative relieve. Since I know that a software update deployment will always do the job, in full. No need for manual triggers or policy modifications.
    Caveats:
    I do realize the fact that – if this would be the scenario - the admin sometimes will not be aware of what might happen during the nightly maint. window since he cannot solely rely on compliance data.
    Anyways:
    This should at least be a deployment option in future releases.
    "Force rescan and deployment re-evaluation after first run." Simple.
    Would make life easier and keep the spread of reboots concentrated to one night and to a minimum. (Given the appropriate length of maint. windows of course)
    Consider things like KB2919355 and how WUAU agent handles that against Windows Update.
    Br,
    Chris

  • Can windows 8 be upgraded to 8.1 through CM 2012 Software Updates deployment?

    Hi,
    Can windows 8 be upgraded to 8.1 through CM 2012 Software Updates deployment rather than having it downloaded through Windows Store?

    The update is not available via software updates. However, if you are doing multiple updates, you can bypass the Windows Store.
    http://www.petri.co.il/upgrade-to-windows-8-1-without-windows-store.htm#
    Gerry Hampson | Blog:
    www.gerryhampsoncm.blogspot.ie | LinkedIn:
    Gerry Hampson | Twitter:
    @gerryhampson

  • Orphaned software update deployment on child site management point

    Hi
    It would appear that we have an orphaned software update deployment still active on our child site management point but is obviously locked due to it's creation on the primary site. It was deleted from the primary site along with package from the DPs
    and these are no longer present. The issue is that the deployment is still active and clients are pulling the selected software updates from it although they are not getting them as they are no longer on the DPs.
    I know that you can take ownership of orphaned packages from the database but can this be done on Software Update deployments?
    If anyone has experienced this issue or knows of a resolve I would be greatly appreciated
    Thanks in advance

    Hi
    It would appear that we have an orphaned software update deployment still active on our child site management point but is obviously locked due to it's creation on the primary site. It was deleted from the primary site along with package from the DPs
    and these are no longer present. The issue is that the deployment is still active and clients are pulling the selected software updates from it although they are not getting them as they are no longer on the DPs.
    I know that you can take ownership of orphaned packages from the database but can this be done on Software Update deployments?
    If anyone has experienced this issue or knows of a resolve I would be greatly appreciated
    Thanks in advance

  • How to find who modified Software Update deployment in sccm 2012

    Hi,
    How to find who modified(Date & Time) software update deployment in SCCM 2012 ?

    In the Console :
    Monitoring / System Status / Status Message Query
    Right Click : "Deployments Created, Modified, or Deleted" - Show Message and select your period.
    You'll have your information there.
    Benoit Lecours | Blog: System Center Dudes

  • Software Update Deployment - Compliance Status = Unknown - Client Check passed/active

    Hi,
    First I want to say, that I found many Forum-Posts which describes a similar issue, but it is not exactly my issue...
    I have a ADR (Auto Deployment Rule) which creates every Month a Windows Update Package, and deploys it. The Deployment starts from a custom day, and ends 14 days later (Deadline). Now I have the issue, that the compliance chek in the deployment status is
    "reseted" every day (at 0:00) - (at least after the Deadline!)... The Compliance Check starts every day at 0:00 and then tries to reach every Computer again! So if the Computer-object is powered on and responding, it turns over to compliant (because
    it is already compliant - the Windows Update Installation works fine...). But if the Computer is not powered on / not responding the next day, it turns over to "Unknown - Client check passed/active" instead of staying in the Status "compliant"
    until it is powered on / respinding again, then it changes over to compliant again... Why is that?
    Is there a issue with the Client Settings?:
    - Software Update Scan (every day)
    - Software Update Re-Evaluation (every day)
    - Compliance Settings (every day at 0:00) -> but is this not for the Configuration Baselines?
    any other ideas?
    Patrik

    As soon as the computer get the Software Update configuration items, it will start compliance checking, then send the compliance check result to MP.
    From your description, the powered on computers sent the state message to the MP when they got the deployment policy. And the frequency of Status Summarizers of updates deployment for a deployment that was modified in the last
    30 days is 60 minutes. Because the site server had not recieved the state message from the powered off computers so that the compliance state was changed to Unknown.
    Juke Chou
    TechNet Community Support

  • Software Update Deployment Compliance Percentage

    I deployed a Software Update group to a collection of computers at the beginning of the week.  I've been monitoring the deployment in the SCCM console and yesterday the compliance % was up to around 25% give or take.  Now today when I look the
    compliance % has dropped back to 0%.  I have tried running the summarization multiple times with no luck.  How can I go about fixing this so I can see which machines have gotten the updates and which have not.  I appreciate any help that anyone
    can offer.  Thanks...

    Those numbers are really only about the deployment and will change when it's reevaluated. To check the compliance of the devices don't use the console as the information might be misleading and/ or misinterpreted. Instead use the reports, more specifically
    the compliance reports. For example Compliance 1 - Overall compliance can be a big help.
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • Error during setup of software update deploy or download.

    Hi,
    We periodically get an error on a single patch download when finishing up the deploy of a software update as shown in the screen shot.
    Does this mean the download is ok except for the one patch or is the entire deploy broke?
    Thanks Lance

    You need to ensure your proxy settings "as the computer" account is to open a command prompt (as admin), and run "psexec -i -s -d cmd" which will open a new command prompt "as the computer" then launch Internet explorer from wherever it resides in c:\program
    files\etc... and try to open that web page from Microsoft that it's having trouble with. i.e.
    http://wsus.ds.downl...oft.com----.exe and see if you can open the file. that will rule out any proxy issues
    Also For this issue, You can refer answer of Jörgen Nilsson in below link
    http://social.technet.microsoft.com/Forums/en-US/6eb3d968-cadc-4aa8-9352-d75d10a72162/automatic-deployment-rule-not-downloading-the-updates?forum=configmanagergeneral
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question, please click "Mark As Answer"
    Mai Ali | My blog: Technical | Twitter:
    Mai Ali

  • Configuring computer restarts after software update deployment deadlines

    I am currently testing in my environment and running pilot deployments at different sites and the way I am doing it is I create deadlines for my test workstations at each site on the Friday following Patch Tuesday at 6PM along with a restart. The problem
    with this though is that if a user takes their laptop home with them, or a workstation is powered down during the deadline, then the next time a workstation comes back online the system will get the notice to restart. 
    I know I can suppress restarts, but that will lower the compliance rate and I really do not want to use maintenance windows for workstations, because I want to reserve maintenance windows for servers only. 
    How do you SCCM MVPs and other SCCM gurus go about doing something like this?
    Thanks

    I suppress all reboots for patches .  I have a DCM rule that detects if a machine is in a pending reboot status.  I build a collection of machines with that pending reboot status DCM rule.  The package refreshes at 2:45AM each day.
    I have a recurring package deployed to the "pending reboot" collection that runs at 3:00AM every day with WOL.  The package checks to see if the machine is still in pending reboot state.  The package checks to  see if the time is
    between 3:00AM and 3:30AM.  If the machine still needs a reboot and it is between 3:00AM and 3:30AM, then the package notifies the user that the machine needs a reboot with a 30 minute countdown.  The user can cancel during the countdown. If the
    user doesn't cancel the machine reboots at the end of the timer.
    If the program is run outside of 3:00AM - 3:30AM, the user is notified that a reboot is necessary, but it does't require a reboot.  
    This works pretty good.  The user gets nagged by Software Updates that a reboot is required, so they can reboot on their own (and that clears the computer from the reboot collection when the DCM rule refreshes.)  If they ignore the reboot, then
    machines that are WOLable or on 24x7 reboot at 3:00AM.  Machines like laptops, the user just gets nagged to death about rebooting, but avoids the real problem of a laptop getting turned on just before a presentation and the user getting forced to reboot
    in front of a crowd of hundreds.  I feel like you should never ever reboot an end users computer without giving them a chance to say no.  The downside is that most other software deployments will fail when a machine is in a pending reboot state -
    so you want to get out of that situation as soon as possible.
     There are a lot of reasons why maintenance windows are impractical.  They are pretty good for servers and other computers that are on 24x7, but are not too good for computers that sleep, and are almost useless for laptops.

  • Software Update deployment errors

    I have a couple of deployments for software update groups where about half of the clients report an error for the deployment status even though some of the updates in the update deployment group do get installed.  The errors are "Failed to install
    update(s) - codes 0X87D00215, 0X800F0902, 0X80070643, 0X7D0024A, and "Failed to download updates(s) - code 0X87dD0015.
    Also the LocacionServices.log on those computers is showing these errors-
    Failed to return the distribution points (0x87d00215)
    Error invoking LSInvokeCallback
    Any suggestions on how to remediate or find the cause of this?  Some clients do install the updates from the update group just fine.

    Hello Joyce,
    For the Location Service Log I get many of these errors:
    Distribution Point='http://server.yoursite.edu/SMS_DP_SMSPKG$/fbce5fed-fa51-4e3c-a900-9ee2ef5659ce', Locality='LOCAL', DPType='SERVER', Version='7958', Capabilities='<Capabilities SchemaVersion="1.0"><Property Name="SSL" Version="1"/><Property
    Name="SSLState" Value="63"/></Capabilities>', Signature='http://server.yoursite.edu/SMS_DP_SMSSIG$/fbce5fed-fa51-4e3c-a900-9ee2ef5659ce.1.tar', ForestTrust='TRUE',
    LocationServices 3/25/2014 4:11:28 PM
    4320 (0x10E0)
    Distribution Point='http://server.yoursite.edu/NOCERT_SMS_DP_SMSPKG$/fbce5fed-fa51-4e3c-a900-9ee2ef5659ce', Locality='LOCAL', DPType='SERVER', Version='7958', Capabilities='<Capabilities SchemaVersion="1.0"><Property Name="SSL" Version="1"/><Property
    Name="SSLState" Value="63"/></Capabilities>', Signature='http://server.yoursite.edu/NOCERT_SMS_DP_SMSSIG$/fbce5fed-fa51-4e3c-a900-9ee2ef5659ce.1.tar', ForestTrust='TRUE',
    LocationServices 3/25/2014 4:11:28 PM
    4320 (0x10E0)
    Distribution Point='net:http://wsus.ds.download.windowsupdate.com/msdownload/update/software/crup/2013/10/excelpp-x-none_f4d377a9fff207774e502b1f8ddd72a7ade998c9.cab', Locality='REMOTE', DPType='WUMU', Version='0', Capabilities='<Capabilities/>', Signature='',
    ForestTrust='FALSE', LocationServices
    3/25/2014 4:11:28 PM 4320 (0x10E0)
    Failed to return the distribution points (0x87d00215)
    LocationServices 3/25/2014 4:11:28 PM
    4320 (0x10E0)
    Error invoking LSInvokeCallback LocationServices
    3/25/2014 4:11:28 PM 4320 (0x10E0)
    In the CAS.log I am seeing these errors:
    Modifying download flags for content request {32EE8135-C8B1-4F5E-B078-6ED78C1BD758} [4000A 0]
    ContentAccess 3/25/2014 5:13:07 AM
    3596 (0x0E0C)
    ICcmContentTransferManager::SetJobFlags failed with error 0x87d00215
    ContentAccess 3/25/2014 5:13:07 AM
    3596 (0x0E0C)
    User policy requested with no user credentials.
    ContentAccess 3/25/2014 12:51:02 PM
    568 (0x0238)
    Invalid user. ContentAccess
    3/25/2014 12:51:02 PM 568 (0x0238)
    Error: DeleteDirectory:- Failed to delete Directory  with Error 0x00000003.
    ContentAccess 3/25/2014 12:51:18 PM
    968 (0x03C8)
    Error: DeleteDirectory:- Failed to delete Directory C:\WINDOWS\ccmcache\16j.BCWork with Error 0x00000002.
    ContentAccess 3/25/2014 12:51:18 PM
    968 (0x03C8)
    I am not seeing any errors in the MP_Framework.log and MP_Location.log logs.  Other clients
    in the same collection are installing the updates just fine.
    The content seems to be fine it just seems to be broken on those computers.  One of my colleagues pushed a client update while some of the systems were applying updates.  It looks like about half of them keep failing on the same updates.  I
    will try to clean out the client cache on a couple of the computers to see if that will clear this problem.  Any other suggestions are welcome.

Maybe you are looking for

  • Problem in FM:WS_DELIVERY_UPDATE to change picked qty and delivery qty

    Dear friends. i am trying to chande picked and del qty's through above fm. i am getting an error message like this: (Required field in interface to delivery update missing 0080000155 000010 VBELN 000000            Message no. VL280 ) i am pasing all

  • Retrieve themes present in a map request or frame

    Hi all, I wanted to know if its possible to retrieve a list of the manually added jdbc themes that are present in a certain map request or map frame? If possible how do we achieve this. Thanks in advance, Avinash

  • ITunes can't find some songs after update

    So I've read a bit about this and it's happened to me now. I did the recent iTunes upgrade and now random song files can't be found. The " ! "shows up here and there. Now when I search for that particular song, I can find and play it. It's just that

  • Keeping library/playlists when only some files moved?

    lost a hard drive unfortunately so many of my itunes files are now not found, with the big ole grey exclamation mark. i had the music i cared about on my ipod, and recovered that, but now if i just import that into my library i will have doubles and

  • PM Sub Order Link with Superior Order

    Hi Experts, Please explain in brief the scenario of Sub Order concept I am trying to use this scenario if we couldn't able to perform number of activities which is in Superior order I am copiying those activities in Sub Order and deleting those activ