Detection Rule in SCCM 2012
I have been deploying some applications through SCCM 2012. Its observed that for some applications
the installation will be successful as per software center. But for uninstallation exits with exit code 1 as per Software center But all the app associated registries and files are deleted. If I retry the uninstallation from software center then
it will be a successful one.
Could some one explain me reason behind this anomaly. And am sure it is not app related.
Hi,
The uninstall command returns exit code 1 the first time it is run so it is applications specific, configuration manager simply reads the exit code and in this case it is 1 so you should examine the uninstall command and why it returns exit code 1.
Regards,
Jörgen
-- My System Center blog ccmexec.com -- Twitter
@ccmexec
Similar Messages
-
Applocker with Windows Installer rules and SCCM 2012
Hi,
We have been running Applocker since two years on Windows 7 Enterprise clients with SCCM 2007 as management and distribution tool.
This setup was working fine until we migrated to SCCM 2012 and started to encounter problems with msi-packages not being able to self-heal when the source was the sccm client cache.
We have recreated this scenario in a lab environment.
Our setup is this:
Windows 2008 R2 (DC)
Windows 7 Enterprise SP1 (Client)
Standard user (not admin)
SCCM 2012 R2 (upgraded from 2007)
Applocker with these rules:
Executable Default rules enabled (Enforced)
Windows Installer Default rules enabled (Enforced)
Exception for %WINDIR% (where SCCM cache is located)
Script Default Rules enabled (Enforced)
Application msi-package with self-heal (omus) and advertised shortcuts
We install the application from the sccm cache (%windir%\ccmcache) and then trigger a self-heal (user components being copied to the user profile).
What we see on the client is: Error 1718. File C:\Windows\ccmcache\54\application.msi was rejected by digital signature policy.
Event log is showing: Event 1008: The installation of
C:\Windows\ccmcache\54\application.msi
is not permitted due to an error in software restriction policy processing. The object cannot be trusted.
It looks like the file cannot be evaluated by Applocker and therefore is not trusted. We get an Access Denied error when testing AppLocker-policy with the following PS-command,
Get-AppLockerPolicy -Effective | Test-AppLockerPolicy -Path C:\Windows\ccmcache\54\application.msi. This command works fine when accessing files in the cache-folder on a SCCM2007-client.
For testing purposes we recreated a similar folder structure: C:\Windows\Folder1\Folder2\application.msi where the user has no permissions on Folder2 and read on the other folders and the File.msi.
This is how the permissions look like in SCCM 2012 (no user permissions on %Windir%\ccmcache). Applocker cannot evaluate the trust-level of application.msi.
The GPO setting “Bypass traverse checking” is set to everyone.
As we can see, the permissions are the same on SCCM 2007 client cache (%Windir%\syswow64\ccm\cache) but we do not have this issue there.
Has anyone got Applocker (with windows installer rules actived) to work with SCCM 2012 and windows installer self-heal?More info. I found some people also encounter this same issue, but specific msi, take a look at
http://social.technet.microsoft.com/Forums/windowsserver/en-US/2ad92754-f01e-410e-97db-7a9bc81586db/msiinstaller-event-1008-when-trying-to-install-3ds-max-2011-after-group-policies-apply-on-domain?forum=winserverGP
Juke Chou
TechNet Community Support -
Automaitc Updates through SCCM 2012 not showing up on the updates status
Hi,
I have configured Automatic Update rule on SCCM 2012 and it works fine but on the client machine i see this.
This is the update status it shows which means updates are not being installed since long time.
But when i see the update history it shows me the latest updates installed.
Why would this happen? please suggest.
Regards,
Maqsood
Maqsood Mohammed Senior Systems Engineer MCITP-Enterprise Admin & ITILv3 Foundation CertifiedHi,
That is as expected as the updates are installed using SCCM and not the Windows Update Agent, if you deploy a client using SCCM OSD and install software updates using SCCM and not WSUS/Windows Update it will actually say:
"Updates were installed: Never"
Regards,
Jörgen
-- My System Center blog ccmexec.com -- Twitter
@ccmexec -
Windows 8.1 clients are not detecting updates deployed to them through SCCM 2012 R2
Hello,
We are using SCCM 2012 R2 to deploy software updates.
On Windows 8.1 SCCM does not show certain updates as being needed and isn't deploying them to the clients even though Windows Update will show them as high importance. These same updates are being detected and deployed to Windows 8 clients successfully.
I believe that the update catalog that WSUS uses may have some incorrect detection rules for the following updates:
2917933
2913320
2913270
2913152
2909569
2904440
2904266
2903939
2899189
2893984
2893294
2892074
2916626
2898785
My automatic deployment rules include Windows 8.1 in the product category. I have even created a standalone rule for Windows 8.1 that builds a new package and the behavior is the same.
We only have a handful of Windows 8+ clients so this hasn't been a big issue but others may want to keep an eye out.I am also running into this issue. After "checking online for updates" on one of my machines in office I found that there were 21 important updates for my 8.1 box. When I cross reference them in SCCM under All Software Updates, it appears these
8.1 updates are not listed. They are however listed for all other OS.
10 seconds after typing this, I went in to verify my WSUS -> Products and Classifications settings and come to find 8.1 and 2012 R2 weren't selected, even though it's an option in SCCM. Go figure! This wasn't the end though. After
running a Synchronization, my issue still wasn't resolved. Went back to check my settings and they again were changed back to having these OS unchecked. Finally, a solution! I found that in SCCM, under Administration tab, Site Configuration
> Sites > ABC - Mysitename, right click and scroll down to "Configure Site Components" > Software Update Point. This setting (although the same as is in WSUS) takes precedence, thus was rolling my settings back to the original configuration
in WSUS.
So long story short, even though my automatic deployment rules stated approve all windows 7/8/8.1 criticals/importants, 8.1 was getting skipped for the most part because my WSUS server wasn't syncing with Microsoft for all of the updates I required. I
did have a couple of updates that squeezed through because they were categorized as "Security Updates for Windows 8, 8.1".
Not sure if this is the solution you were looking for, but your thread got me started in the right direction, hopefully this response helps in the same way!
Thanks! -
Detection State 'Unknown' in SCCM 2012 Software Compliance Report
My management is looking for windows patches compliance reports from SCCM 2012
When I am trying to prepare Compliance Reports with SCCM 2012 for windows patches, I am noticing that I have lots of patches, where "Unknown" state is showing against many Windows Patches. I was expecting the reports to show “Not Required"
instead of "Unknown".
Please tell me, where the issue might be and how to rectify it.
Thanks in advance.Thanks for your reply Jorgen. Is there anyway I can initiate a " Software Update Scan on all Clients from SCCM Console? If yes, please let me steps- how?
As a test, I run "Software scan from a client and client report back to server. However on WindowsUpdates.log I can see some unhappy logs.
Does it mean that WSUS server and clients are having some issue?
2014-08-03 16:43:56:773 840 1668 AU ## END ## AU: Search for updates [CallId = {6E29C07F-4A2B-4137-8228-D47F81523EFD}]
2014-08-03 16:43:56:773 840 1668 AU #############
2014-08-03 16:43:56:773 840 1668 AU AU setting next detection timeout to 2014-08-03 11:43:56
2014-08-03 16:44:01:664 840 110c Report REPORT EVENT: {F5E38138-DE94-45D1-A8D0-79C4C8667568} 2014-08-03 16:43:56:664+1000 1 148 101 {D67661EB-2423-451D-BF5D-13199E37DF28} 0 800b0001 SelfUpdate Failure Software
Synchronization Windows Update Client failed to detect with error 0x800b0001.
2014-08-03 21:43:56:923 840 a4c AU #############
2014-08-03 21:43:56:923 840 a4c AU ## START ## AU: Search for updates
2014-08-03 21:43:56:923 840 a4c AU #########
2014-08-03 21:43:56:923 840 a4c AU <<## SUBMITTED ## AU: Search for updates [CallId = {B4CB615A-9D97-4933-947F-556215D85E59}]
2014-08-03 21:43:56:923 840 d58 Agent *************
2014-08-03 21:43:56:923 840 d58 Agent ** START ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-08-03 21:43:56:923 840 d58 Agent *********
2014-08-03 21:43:56:923 840 d58 Agent * Online = Yes; Ignore download priority = No
2014-08-03 21:43:56:923 840 d58 Agent * Criteria = "IsHidden=0 and IsInstalled=0 and DeploymentAction='Installation' and IsAssigned=1 or IsHidden=0 and IsPresent=1 and DeploymentAction='Uninstallation' and IsAssigned=1
or IsHidden=0 and IsInstalled=1 and DeploymentAction='Installation' and IsAssigned=1 and RebootRequired=1 or IsHidden=0 and IsInstalled=0 and DeploymentAction='Uninstallation' and IsAssigned=1 and RebootRequired=1"
2014-08-03 21:43:56:923 840 d58 Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2014-08-03 21:43:56:923 840 d58 Agent * Search Scope = {Machine}
2014-08-03 21:43:57:439 840 d58 Misc Validating signature for C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wuident.cab:
2014-08-03 21:43:57:454 840 d58 Misc Microsoft signed: Yes
2014-08-03 21:43:57:454 840 d58 Misc WARNING: Digital Signatures on file C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wuident.cab are not trusted: Error 0x800b0001
2014-08-03 21:43:57:454 840 d58 Setup FATAL: IsUpdateRequired failed with error 0x800b0001
2014-08-03 21:43:57:454 840 d58 Setup WARNING: SelfUpdate: Default Service: IsUpdateRequired failed: 0x800b0001
2014-08-03 21:43:57:454 840 d58 Setup WARNING: SelfUpdate: Default Service: IsUpdateRequired failed, error = 0x800B0001
2014-08-03 21:43:57:454 840 d58 Agent * WARNING: Skipping scan, self-update check returned 0x800B0001
2014-08-03 21:43:58:782 840 d58 Agent * WARNING: Exit code = 0x800B0001
2014-08-03 21:43:58:782 840 d58 Agent *********
2014-08-03 21:43:58:782 840 d58 Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-08-03 21:43:58:782 840 d58 Agent *************
2014-08-03 21:43:58:782 840 d58 Agent WARNING: WU client failed Searching for update with error 0x800b0001
2014-08-03 21:43:58:782 840 11f8 AU >>## RESUMED ## AU: Search for updates [CallId = {B4CB615A-9D97-4933-947F-556215D85E59}]
2014-08-03 21:43:58:782 840 11f8 AU # WARNING: Search callback failed, result = 0x800B0001
2014-08-03 21:43:58:782 840 11f8 AU # WARNING: Failed to find updates with error code 800B0001
2014-08-03 21:43:58:782 840 11f8 AU #########
2014-08-03 21:43:58:782 840 11f8 AU ## END ## AU: Search for updates [CallId = {B4CB615A-9D97-4933-947F-556215D85E59}]
2014-08-03 21:43:58:782 840 11f8 AU #############
2014-08-03 21:43:58:782 840 11f8 AU AU setting next detection timeout to 2014-08-03 16:43:58
2014-08-03 21:44:02:454 840 d58 Report REPORT EVENT: {5653D57E-2599-426E-B3F2-3F626EDC9C8D} 2014-08-03 21:43:57:454+1000 1 148 101 {D67661EB-2423-451D-BF5D-13199E37DF28} 0 800b0001 SelfUpdate Failure Software
Synchronization Windows Update Client failed to detect with error 0x800b0001.
2014-08-04 02:43:59:327 840 a4c AU #############
2014-08-04 02:43:59:327 840 a4c AU ## START ## AU: Search for updates
2014-08-04 02:43:59:327 840 a4c AU #########
2014-08-04 02:43:59:327 840 a4c AU <<## SUBMITTED ## AU: Search for updates [CallId = {EBB099BD-7E1E-481B-B354-1DF2CD3AB53F}]
2014-08-04 02:43:59:327 840 1528 Agent *************
2014-08-04 02:43:59:327 840 1528 Agent ** START ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-08-04 02:43:59:327 840 1528 Agent *********
2014-08-04 02:43:59:327 840 1528 Agent * Online = Yes; Ignore download priority = No
2014-08-04 02:43:59:327 840 1528 Agent * Criteria = "IsHidden=0 and IsInstalled=0 and DeploymentAction='Installation' and IsAssigned=1 or IsHidden=0 and IsPresent=1 and DeploymentAction='Uninstallation' and IsAssigned=1
or IsHidden=0 and IsInstalled=1 and DeploymentAction='Installation' and IsAssigned=1 and RebootRequired=1 or IsHidden=0 and IsInstalled=0 and DeploymentAction='Uninstallation' and IsAssigned=1 and RebootRequired=1"
2014-08-04 02:43:59:327 840 1528 Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2014-08-04 02:43:59:327 840 1528 Agent * Search Scope = {Machine}
2014-08-04 02:43:59:858 840 1528 Misc Validating signature for C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wuident.cab:
2014-08-04 02:43:59:858 840 1528 Misc Microsoft signed: Yes
2014-08-04 02:43:59:858 840 1528 Misc WARNING: Digital Signatures on file C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wuident.cab are not trusted: Error 0x800b0001
2014-08-04 02:43:59:858 840 1528 Setup FATAL: IsUpdateRequired failed with error 0x800b0001
2014-08-04 02:43:59:858 840 1528 Setup WARNING: SelfUpdate: Default Service: IsUpdateRequired failed: 0x800b0001
2014-08-04 02:43:59:858 840 1528 Setup WARNING: SelfUpdate: Default Service: IsUpdateRequired failed, error = 0x800B0001
2014-08-04 02:43:59:858 840 1528 Agent * WARNING: Skipping scan, self-update check returned 0x800B0001
2014-08-04 02:44:00:577 840 1528 Agent * WARNING: Exit code = 0x800B0001
2014-08-04 02:44:00:577 840 1528 Agent *********
2014-08-04 02:44:00:577 840 1528 Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-08-04 02:44:00:577 840 1528 Agent *************
2014-08-04 02:44:00:577 840 1528 Agent WARNING: WU client failed Searching for update with error 0x800b0001
2014-08-04 02:44:00:577 840 1018 AU >>## RESUMED ## AU: Search for updates [CallId = {EBB099BD-7E1E-481B-B354-1DF2CD3AB53F}]
2014-08-04 02:44:00:577 840 1018 AU # WARNING: Search callback failed, result = 0x800B0001
2014-08-04 02:44:00:577 840 1018 AU # WARNING: Failed to find updates with error code 800B0001
2014-08-04 02:44:00:577 840 1018 AU #########
2014-08-04 02:44:00:577 840 1018 AU ## END ## AU: Search for updates [CallId = {EBB099BD-7E1E-481B-B354-1DF2CD3AB53F}]
2014-08-04 02:44:00:577 840 1018 AU #############
2014-08-04 02:44:00:577 840 1018 AU AU setting next detection timeout to 2014-08-03 21:44:00
2014-08-04 02:44:04:859 840 1528 Report REPORT EVENT: {3121ED76-441E-4862-A90B-9AF1B5170B85} 2014-08-04 02:43:59:858+1000 1 148 101 {D67661EB-2423-451D-BF5D-13199E37DF28} 0 800b0001 SelfUpdate Failure Software
Synchronization Windows Update Client failed to detect with error 0x800b0001.
2014-08-04 07:44:00:725 840 a4c AU #############
2014-08-04 07:44:00:725 840 a4c AU ## START ## AU: Search for updates
2014-08-04 07:44:00:725 840 a4c AU #########
2014-08-04 07:44:00:725 840 a4c AU <<## SUBMITTED ## AU: Search for updates [CallId = {CC637D7F-C439-4E83-A71D-645B2CD92B8A}]
2014-08-04 07:44:00:725 840 11f0 Agent *************
2014-08-04 07:44:00:725 840 11f0 Agent ** START ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-08-04 07:44:00:725 840 11f0 Agent *********
2014-08-04 07:44:00:725 840 11f0 Agent * Online = Yes; Ignore download priority = No
2014-08-04 07:44:00:725 840 11f0 Agent * Criteria = "IsHidden=0 and IsInstalled=0 and DeploymentAction='Installation' and IsAssigned=1 or IsHidden=0 and IsPresent=1 and DeploymentAction='Uninstallation' and IsAssigned=1
or IsHidden=0 and IsInstalled=1 and DeploymentAction='Installation' and IsAssigned=1 and RebootRequired=1 or IsHidden=0 and IsInstalled=0 and DeploymentAction='Uninstallation' and IsAssigned=1 and RebootRequired=1"
2014-08-04 07:44:00:725 840 11f0 Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2014-08-04 07:44:00:725 840 11f0 Agent * Search Scope = {Machine}
2014-08-04 07:44:01:178 840 11f0 Misc Validating signature for C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wuident.cab:
2014-08-04 07:44:01:178 840 11f0 Misc Microsoft signed: Yes
2014-08-04 07:44:01:178 840 11f0 Misc WARNING: Digital Signatures on file C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wuident.cab are not trusted: Error 0x800b0001
2014-08-04 07:44:01:178 840 11f0 Setup FATAL: IsUpdateRequired failed with error 0x800b0001
2014-08-04 07:44:01:178 840 11f0 Setup WARNING: SelfUpdate: Default Service: IsUpdateRequired failed: 0x800b0001
2014-08-04 07:44:01:178 840 11f0 Setup WARNING: SelfUpdate: Default Service: IsUpdateRequired failed, error = 0x800B0001
2014-08-04 07:44:01:178 840 11f0 Agent * WARNING: Skipping scan, self-update check returned 0x800B0001
2014-08-04 07:44:01:803 840 11f0 Agent * WARNING: Exit code = 0x800B0001
2014-08-04 07:44:01:803 840 11f0 Agent *********
2014-08-04 07:44:01:803 840 11f0 Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-08-04 07:44:01:803 840 11f0 Agent *************
2014-08-04 07:44:01:803 840 11f0 Agent WARNING: WU client failed Searching for update with error 0x800b0001
2014-08-04 07:44:01:803 840 14dc AU >>## RESUMED ## AU: Search for updates [CallId = {CC637D7F-C439-4E83-A71D-645B2CD92B8A}]
2014-08-04 07:44:01:803 840 14dc AU # WARNING: Search callback failed, result = 0x800B0001
2014-08-04 07:44:01:803 840 14dc AU # WARNING: Failed to find updates with error code 800B0001
2014-08-04 07:44:01:803 840 14dc AU #########
2014-08-04 07:44:01:803 840 14dc AU ## END ## AU: Search for updates [CallId = {CC637D7F-C439-4E83-A71D-645B2CD92B8A}]
2014-08-04 07:44:01:803 840 14dc AU #############
2014-08-04 07:44:01:803 840 14dc AU AU setting next detection timeout to 2014-08-04 02:44:01
2014-08-04 07:44:06:178 840 11f0 Report REPORT EVENT: {5CC4BC72-612B-4C93-B560-57DEBEF9DD30} 2014-08-04 07:44:01:178+1000 1 148 101 {D67661EB-2423-451D-BF5D-13199E37DF28} 0 800b0001 SelfUpdate Failure Software
Synchronization Windows Update Client failed to detect with error 0x800b0001.
2014-08-04 07:56:20:733 840 a4c AU AU was unable to detect updates for more than 48 hours
2014-08-04 07:56:25:733 840 11f0 Report REPORT EVENT: {BFD85143-59AD-4E15-9797-4CEE9D7F089F} 2014-08-04 07:56:20:733+1000 1 149 102 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Failure Software
Synchronization Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection.
2014-08-04 12:44:01:690 840 a4c AU #############
2014-08-04 12:44:01:690 840 a4c AU ## START ## AU: Search for updates
2014-08-04 12:44:01:690 840 a4c AU #########
2014-08-04 12:44:01:690 840 a4c AU <<## SUBMITTED ## AU: Search for updates [CallId = {16B8EC72-AD9E-47D5-9F94-73794A653572}]
2014-08-04 12:44:01:690 840 1320 Agent *************
2014-08-04 12:44:01:690 840 1320 Agent ** START ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-08-04 12:44:01:690 840 1320 Agent *********
2014-08-04 12:44:01:690 840 1320 Agent * Online = Yes; Ignore download priority = No
2014-08-04 12:44:01:690 840 1320 Agent * Criteria = "IsHidden=0 and IsInstalled=0 and DeploymentAction='Installation' and IsAssigned=1 or IsHidden=0 and IsPresent=1 and DeploymentAction='Uninstallation' and IsAssigned=1
or IsHidden=0 and IsInstalled=1 and DeploymentAction='Installation' and IsAssigned=1 and RebootRequired=1 or IsHidden=0 and IsInstalled=0 and DeploymentAction='Uninstallation' and IsAssigned=1 and RebootRequired=1"
2014-08-04 12:44:01:690 840 1320 Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2014-08-04 12:44:01:690 840 1320 Agent * Search Scope = {Machine}
2014-08-04 12:44:02:143 840 1320 Misc Validating signature for C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wuident.cab:
2014-08-04 12:44:02:174 840 1320 Misc Microsoft signed: Yes
2014-08-04 12:44:02:174 840 1320 Misc WARNING: Digital Signatures on file C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wuident.cab are not trusted: Error 0x800b0001
2014-08-04 12:44:02:174 840 1320 Setup FATAL: IsUpdateRequired failed with error 0x800b0001
2014-08-04 12:44:02:174 840 1320 Setup WARNING: SelfUpdate: Default Service: IsUpdateRequired failed: 0x800b0001
2014-08-04 12:44:02:174 840 1320 Setup WARNING: SelfUpdate: Default Service: IsUpdateRequired failed, error = 0x800B0001
2014-08-04 12:44:02:174 840 1320 Agent * WARNING: Skipping scan, self-update check returned 0x800B0001
2014-08-04 12:44:02:268 840 1320 Agent * WARNING: Exit code = 0x800B0001
2014-08-04 12:44:02:268 840 1320 Agent *********
2014-08-04 12:44:02:268 840 1320 Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-08-04 12:44:02:268 840 1320 Agent *************
2014-08-04 12:44:02:268 840 1320 Agent WARNING: WU client failed Searching for update with error 0x800b0001
2014-08-04 12:44:02:268 840 11a8 AU >>## RESUMED ## AU: Search for updates [CallId = {16B8EC72-AD9E-47D5-9F94-73794A653572}]
2014-08-04 12:44:02:268 840 11a8 AU # WARNING: Search callback failed, result = 0x800B0001
2014-08-04 12:44:02:268 840 11a8 AU # WARNING: Failed to find updates with error code 800B0001
2014-08-04 12:44:02:268 840 11a8 AU #########
2014-08-04 12:44:02:268 840 11a8 AU ## END ## AU: Search for updates [CallId = {16B8EC72-AD9E-47D5-9F94-73794A653572}]
2014-08-04 12:44:02:268 840 11a8 AU #############
2014-08-04 12:44:02:268 840 11a8 AU AU setting next detection timeout to 2014-08-04 07:44:02
2014-08-04 12:44:07:174 840 1320 Report REPORT EVENT: {01CB1C52-239F-4DB7-A4AF-C0FBF2E5358A} 2014-08-04 12:44:02:174+1000 1 148 101 {D67661EB-2423-451D-BF5D-13199E37DF28} 0 800b0001 SelfUpdate Failure Software
Synchronization Windows Update Client failed to detect with error 0x800b0001.
2014-08-04 16:24:12:878 2748 bc0 COMAPI -------------
2014-08-04 16:24:12:878 2748 bc0 COMAPI -- START -- COMAPI: Search [ClientId = CcmExec]
2014-08-04 16:24:12:878 2748 bc0 COMAPI ---------
2014-08-04 16:24:12:878 2748 bc0 COMAPI <<-- SUBMITTED -- COMAPI: Search [ClientId = CcmExec]
2014-08-04 16:24:12:878 840 1438 Agent *************
2014-08-04 16:24:12:878 840 1438 Agent ** START ** Agent: Finding updates [CallerId = CcmExec]
2014-08-04 16:24:12:878 840 1438 Agent *********
2014-08-04 16:24:12:878 840 1438 Agent * Include potentially superseded updates
2014-08-04 16:24:12:878 840 1438 Agent * Online = Yes; Ignore download priority = Yes
2014-08-04 16:24:12:878 840 1438 Agent * Criteria = "(DeploymentAction=* AND Type='Software') OR (DeploymentAction=* AND Type='Driver')"
2014-08-04 16:24:12:878 840 1438 Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2014-08-04 16:24:12:878 840 1438 Agent * Search Scope = {Machine}
2014-08-04 16:24:27:769 840 1438 PT +++++++++++ PT: Synchronizing server updates +++++++++++
2014-08-04 16:24:27:769 840 1438 PT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL =
http://S-Syd-SCCM.xxx.xxx:80/ClientWebService/client.asmx
2014-08-04 16:24:27:816 840 1438 PT WARNING: Cached cookie has expired or new PID is available
2014-08-04 16:24:27:816 840 1438 PT Initializing simple targeting cookie, clientId = fcdcdbf8-529a-414d-9679-9bfbeac1626c, target group = , DNS name = server-util.xxx.xxx
2014-08-04 16:24:27:816 840 1438 PT Server URL =
http://S-Syd-SCCM.xxx.xxx:80/SimpleAuthWebService/SimpleAuth.asmx
2014-08-04 16:24:28:925 840 1438 Agent WARNING: Failed to evaluate Installed rule, updateId = {07AEE973-703C-4F27-83F1-3E764D9ED2C7}.202, hr = 80041010
2014-08-04 16:25:12:270 840 1438 PT +++++++++++ PT: Synchronizing extended update info +++++++++++
2014-08-04 16:25:12:270 840 1438 PT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL =
http://S-Syd-SCCM.xxx.xxx:80/ClientWebService/client.asmx
2014-08-04 16:25:19:083 840 a4c AU Triggering Offline detection (non-interactive)
2014-08-04 16:25:19:083 840 a4c AU #############
2014-08-04 16:25:19:083 840 a4c AU ## START ## AU: Search for updates
2014-08-04 16:25:19:083 840 a4c AU #########
2014-08-04 16:25:19:083 840 1438 Agent * Added update {1E3A5101-3621-458B-B208-5ED11473EFFF}.101 to search result
16:25:19:083 840 1438 Agent * Added update {E8A49607-7F8E-47CB-A487-A7465B733A7D}.103 to search result
2014-08-04 16:25:19:083 840 a4c AU <<## SUBMITTED ## AU: Search for updates [CallId = {08745433-443F-4A94-A1C7-44314DA6B63C}]
2014-08-04 16:25:19:083 840 1438 Agent * Added update {CF3B6409-EBE7-462B-89BE-CF0F9754139F}.101 to search result
2014-08-04 16:25:19:099 840 1438 Agent Bundle contains no deployed children and thus is invalid.
2014-08-04 16:25:19:099 840 1438 Agent Update {3FEFB63F-4DFC-49C4-85DB-D40DD6EA3F22}.102 is not a valid bundle. Not returning it.
2014-08-04 16:25:19:114 840 1438 Agent * Added update {D5F76FFF-AC16-4460-99FE-FB8334F65970}.101 to search result
2014-08-04 16:25:19:146 840 1438 Agent * Found 294 updates and 78 categories in search; evaluated appl. rules of 2660 out of 5182 deployed entities
2014-08-04 16:25:19:739 840 1438 Agent *********
2014-08-04 16:25:19:739 840 1438 Agent ** END ** Agent: Finding updates [CallerId = CcmExec]
2014-08-04 16:25:19:739 840 1438 Agent *************
2014-08-04 16:25:19:786 840 1438 Agent *************
2014-08-04 16:25:19:786 840 1438 Agent ** START ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-08-04 16:25:19:786 840 1438 Agent *********
2014-08-04 16:25:19:786 840 1438 Agent * Online = No; Ignore download priority = No
2014-08-04 16:25:19:786 840 1438 Agent * Criteria = "IsHidden=0 and IsInstalled=0 and DeploymentAction='Installation' and IsAssigned=1 or IsHidden=0 and IsPresent=1 and DeploymentAction='Uninstallation' and IsAssigned=1
or IsHidden=0 and IsInstalled=1 and DeploymentAction='Installation' and IsAssigned=1 and RebootRequired=1 or IsHidden=0 and IsInstalled=0 and DeploymentAction='Uninstallation' and IsAssigned=1 and RebootRequired=1"
2014-08-04 16:25:19:786 840 1438 Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2014-08-04 16:25:19:786 840 1438 Agent * Search Scope = {Machine}
2014-08-04 16:25:19:802 2748 13ec COMAPI >>-- RESUMED -- COMAPI: Search [ClientId = CcmExec]
2014-08-04 16:25:20:036 2748 13ec COMAPI - Updates found = 294
2014-08-04 16:25:20:036 2748 13ec COMAPI ---------
2014-08-04 16:25:20:036 2748 13ec COMAPI -- END -- COMAPI: Search [ClientId = CcmExec]
2014-08-04 16:25:20:036 2748 13ec COMAPI -------------
2014-08-04 16:25:22:208 840 1438 Agent * Found 0 updates and 78 categories in search; evaluated appl. rules of 251 out of 5182 deployed entities
2014-08-04 16:25:22:302 840 1438 Agent *********
2014-08-04 16:25:22:302 840 1438 Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-08-04 16:25:22:302 840 1438 Agent *************
2014-08-04 16:25:22:349 840 4bc AU >>## RESUMED ## AU: Search for updates [CallId = {08745433-443F-4A94-A1C7-44314DA6B63C}]
2014-08-04 16:25:22:349 840 4bc AU # 0 updates detected
2014-08-04 16:25:22:349 840 4bc AU #########
2014-08-04 16:25:22:349 840 4bc AU ## END ## AU: Search for updates [CallId = {08745433-443F-4A94-A1C7-44314DA6B63C}]
2014-08-04 16:25:22:349 840 4bc AU #############
2014-08-04 16:25:22:349 840 4bc AU Featured notifications is disabled.
2014-08-04 16:25:22:349 840 1438 Report REPORT EVENT: {547C4CB0-3015-402C-A5DF-9B6B1F900864} 2014-08-04 16:25:19:724+1000 1 147 101 {00000000-0000-0000-0000-000000000000} 0 0 CcmExec Success Software
Synchronization Windows Update Client successfully detected 294 updates.
2014-08-04 16:25:22:349 840 1438 Report REPORT EVENT: {22C743C2-863C-4A90-87E3-C8A81850A45B} 2014-08-04 16:25:19:724+1000 1 156 101 {00000000-0000-0000-0000-000000000000} 0 0 CcmExec Success Pre-Deployment
Check Reporting client status. -
SCCM 2012 R2 not show Threat item in Malware Detected Report.
I had no "Malware detected" items fount.
There are no report abount virus that Endpoint Protection client finds.
I try to test be creating file with this test content: "X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*", my Endpoint Protection find this file, logging it in its journal, but SCCM not show this Theat.
My computer was discovered, Endpoint Protection was automatic installed, Antimalware Policies work fine...
....but in "Monitoring/Endpoint Protection Status/System Center 2012 R2 Endpoint Protection Status" my collection with my computer(this is test collection), show me: "Endpoint Protection agent
not yet installed: 1"
There are many collection with many devices, but no one give me report about "Malware Detected", but virus was found in our company.
SCCM 2012 R2 was upgrade from older version(i have not this information).
What log must i fount about this issue?
What cat i do to fix this problem?SCEP client is installed by policy successfull.
Policy applied succesfull too.
but i guess that data do not copy from SCEP to SCCM
or data do not inserted in database.
CcmMessaging.log:
Raising event:
instance of CCM_CcmHttp_Status
ClientID = "GUID:EFA60F96-CEE9-470B-8A3D-FD8453D1D7C2";
DateTime = "20140410103213.874000+000";
HostName = "SCCM2012.DOMAIN.LOC";
HRESULT = "0x00000000";
ProcessID = 2764;
StatusCode = 0;
ThreadID = 12908;
Could not load logging configuration for component CcmTask. Using default values.
Could not load logging configuration for component FileSystemFile. Using default values.
Supplied sender token is null. Using GetUserTokenFromSid to find sender's token.
mpfdm.log:
PULL:Worker thread [Site System Status Summarizer] checking for *.SUM files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\sitestat.box. SMS_MP_FILE_DISPATCH_MANAGER
10.04.2014 16:42:17 12200 (0x2FA8)
PULL:Worker thread [Discovery Data Manager (Trusted)] checking for *.UDR files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\ddr.box. SMS_MP_FILE_DISPATCH_MANAGER
10.04.2014 16:42:17 25480 (0x6388)
PULL:Worker thread [State System (Incoming - high priority)] checking for *.SMX files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\statemsg.box\high.
SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014 16:42:17 5660 (0x161C)
PULL:Worker thread [Status Manager] checking for *.SVF files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\stat.box. SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014
16:42:17 30604 (0x778C)
PULL:Worker thread [State System (Incoming - low priority)] checking for *.SMX files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\statemsg.box\low.
SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014 16:42:17 12176 (0x2F90)
PULL:Worker thread [Software Metering Processor Usage (Site)] checking for *.MUX files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\swm.box.
SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014 16:42:17 17576 (0x44A8)
PULL:Worker thread [State System (Incoming - high priority)] checking for *.SME files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\statemsg.box\high.
SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014 16:42:17 10552 (0x2938)
PULL:Worker thread [Successful Policy Requests] checking for *.POL files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\polreq.box. SMS_MP_FILE_DISPATCH_MANAGER
10.04.2014 16:42:17 19480 (0x4C18)
PULL:Worker thread [Notification Manager] checking for *.BOS files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\bgb.box. SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014
16:42:17 11276 (0x2C0C)
PULL:Worker thread [Software Inventory Processor (Site Trusted)] checking for *.SI? files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\sinv.box.
SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014 16:42:17 23188 (0x5A94)
PULL:Worker thread [Notification Manager] checking for *.BTS files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\bgb.box. SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014
16:42:17 17444 (0x4424)
PULL:Worker thread [State System (Incoming - low priority)] checking for *.SME files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\statemsg.box\low.
SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014 16:42:17 18876 (0x49BC)
PULL:Worker thread [Discovery Data Manager (Trusted)] checking for *.DDR files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\ddr.box. SMS_MP_FILE_DISPATCH_MANAGER
10.04.2014 16:42:17 9008 (0x2330)
PULL:Worker thread [Hierarchy Manager (Forwarding messages)] checking for *.MCM files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\MCM.box.
SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014 16:42:17 29416 (0x72E8)
PULL:Worker thread [Asset Intelligence KB Manager] checking for *.AR? files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\AIKbMgr.box. SMS_MP_FILE_DISPATCH_MANAGER
10.04.2014 16:42:17 3960 (0x0F78)
PULL:Worker thread [Discovery Data Manager (Registration)] checking for *.RDR files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\rdr.box. SMS_MP_FILE_DISPATCH_MANAGER
10.04.2014 16:42:17 11744 (0x2DE0)
PULL:Worker thread [Endpoint Protection Manager] checking for *.EPP files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\EPMgr.box. SMS_MP_FILE_DISPATCH_MANAGER
10.04.2014 16:42:17 25272 (0x62B8)
PULL:Worker thread [SMS_AMT_PROXY_COMPONENT] checking for *.APX files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\amtproxy.box. SMS_MP_FILE_DISPATCH_MANAGER
10.04.2014 16:42:17 26296 (0x66B8)
PULL:Worker thread [State System (Incoming)] checking for *.SME files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\statemsg.box. SMS_MP_FILE_DISPATCH_MANAGER
10.04.2014 16:42:17 25908 (0x6534)
PULL:Worker thread [State System (Incoming)] checking for *.SMF files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\statemsg.box. SMS_MP_FILE_DISPATCH_MANAGER
10.04.2014 16:42:17 25468 (0x637C)
PULL:Worker thread [State System (Incoming)] checking for *.SMX files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\statemsg.box. SMS_MP_FILE_DISPATCH_MANAGER
10.04.2014 16:42:17 10148 (0x27A4)
PULL:Worker thread [SMS_AMT_PROXY_COMPONENT] checking for *.OTP files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\amtproxy.box. SMS_MP_FILE_DISPATCH_MANAGER
10.04.2014 16:42:17 30220 (0x760C)
PULL:Worker thread [Distribution Manager (Incoming)] checking for *.STA files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\distmgr.box. SMS_MP_FILE_DISPATCH_MANAGER
10.04.2014 16:42:18 13872 (0x3630)
PULL:Worker thread [Distribution Manager (Incoming)] checking for *.DMD files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\distmgr.box. SMS_MP_FILE_DISPATCH_MANAGER
10.04.2014 16:42:18 30448 (0x76F0)
PULL:Worker thread [Site Server Inventory Collection] checking for *.NHM files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\hinv.box. SMS_MP_FILE_DISPATCH_MANAGER
10.04.2014 16:42:18 27100 (0x69DC)
PULL:Worker thread [Data Loader (Trusted)] checking for *.MIF files in \\SQLSRV.DOMAIN.LOC\D$\SMS\MP\OUTBOXES\hinv.box. SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014
16:42:18 2452 (0x0994)
The machine account will be used for ["Display=\\NV-WSUS.DOMAIN.LOC\"]MSWNET:["SMS_SITE=EKB"]\\NV-WSUS.DOMAIN.LOC\. SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014
16:43:43 5316 (0x14C4)
Successfully made a network connection to \\NV-WSUS.DOMAIN.LOC\ADMIN$. SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014 16:43:43 5316 (0x14C4)
NV-WSUS.DOMAIN.LOC is pushing files. Mode must be push. SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014 16:43:43 5316 (0x14C4)
Cancelling network connection to \\NV-WSUS.DOMAIN.LOC\ADMIN$. SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014 16:43:43 5316 (0x14C4)
Successfully logged on user DOMAIN.LOC\sccm-installer (Token = 00000000000032FC) and impersonated for accessing ["Display=\\SQLSRV.DOMAIN.LOC\"]MSWNET:
["SMS_SITE=EKB"]\\SQLSRV.DOMAIN.LOC\. SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014 16:43:43 5316 (0x14C4)
Successfully made a network connection to \\SQLSRV.DOMAIN.LOC\ADMIN$. SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014 16:43:43 5316 (0x14C4)
Pulling files from SQLSRV.DOMAIN.LOC. Mode must be pull. SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014 16:43:43 5316 (0x14C4)
Cancelling network connection to \\SQLSRV.DOMAIN.LOC\ADMIN$. SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014 16:43:43 5316 (0x14C4)
Reverting current impersonation. SMS_MP_FILE_DISPATCH_MANAGER 10.04.2014 16:43:43 5316 (0x14C4)
statesys.log:
CMessageProcessor - Processing file: g1a2vm9n.SMX SMS_STATE_SYSTEM 10.04.2014 16:43:13 25096 (0x6208)
*** *** Unknown SQL Error! SMS_STATE_SYSTEM 10.04.2014 16:43:13 25096 (0x6208)
CMessageProcessor - Encountered a non-fatal SQL error while processing SMS_STATE_SYSTEM 10.04.2014 16:43:13 25096 (0x6208)
CMessageProcessor - Non-fatal error while processing g1a2vm9n.SMX SMS_STATE_SYSTEM 10.04.2014 16:43:13 25096 (0x6208)
STATMSG: ID=6104 SEV=E LEV=M SOURCE="SMS Server" COMP="SMS_STATE_SYSTEM" SYS=SCCM2012.kontur SITE=EKB PID=6388 TID=25096 GMTDATE=Чт апр 10 10:43:13.059 2014
ISTR0="g1a2vm9n.SMX" ISTR1="" ISTR2="" ISTR3="" ISTR4="" ISTR5="" ISTR6="" ISTR7="" ISTR8="" ISTR9="" NUMATTRS=0 SMS_STATE_SYSTEM 10.04.2014 16:43:13
25096 (0x6208)
Thread "State Message Processing Thread #0" id:25096 was unable to process file "C:\Program Files\Microsoft Configuration Manager\inboxes\auth\statesys.box\process
\g1a2vm9n.SMX", moving to corrupt directory. SMS_STATE_SYSTEM 10.04.2014 16:43:13 25096 (0x6208) -
Hi,
I followed this manual to configure forefront endpoint protection on clients: http://www.windows-noob.com/forums/index.php?/topic/6106-using-system-center-2012-configuration-manager-part-6-adding-the-endpoint-protection-role-configure-alerts-and-custom-antimalware-policies/
Now in short: everything works fine ... as long as I trigger the audomatic deployment rules.
Current situation:
1. ADR ran fine (3:30 this night)
2.Software update group is NOT ok
3.I run ADR manually (right click on ADR, run)
4.software update group is ok (green icon)
Then virusupdates are succesfull. This means that clients only update their virus definitions when I manually run the ADR-rule.
I'm missing something here.
Please advise.
J.
Jan HoedtProbably this issue: http://social.technet.microsoft.com/Forums/en-US/c6109678-785b-4c6d-9cb4-c9dfc1e34b2e/sccm-2012-automatic-deployment-rule-not-executing-updates-for-scep?forum=configmanagerapps
Iow: wsus updates were scheduled at 3, automatic update rules at 3:15, probably sync wasn't done yet so it doesn't find updates. "The day after" updates are marked as expired.
Jan Hoedt -
SCCM 2012 does not detect MS14-001 KB2837577 as required
SCCM 2012 does not detect MS14-001 KB2837577 (Security Update for Microsoft SharePoint Server 2010) as being required. I am able to install it manually. However, I would expect and like this to be deployed via System Center Configuration Manager.
Hi,
You might also need to analyze the updates installation logs on the client to see whether there are any useful information. (UpdatesStore.log, UpdatesHandler.log, UpdateDeployment.log and WUAHandler.log)
http://technet.microsoft.com/en-us/library/hh427342.aspx#BKMK_SU_NAPLog
Best Regards,
Joyce Li
We
are trying to better understand customer views on social support experience, so your participation in this
interview project would be greatly appreciated if you have time.
Thanks for helping make community forums a great place. -
SCCM 2012 - IE10 - Detection Method - Compliance?
Hi, I am successfully deploying IE10 to the domain. I have amended the detection method to the below:
i have updated the content. How do I update the compliance to reflect to the deployment as it is still @ 0% for each Collection? Do i need to redeploy the application?. I need to get the results asap if possible!
ThanksHello, there is still no change in the Compliance. I have changed the Detection Rule to
Operator: Greater than or Equal to rather than Equals:
Hoping this will make a difference or any more solutions? Cheers -
Upgrade from SCCM 2012 SP1 CU4 to R2 Fails - Unsupported Upgrade Path
Hi everybody,
I'm currently upgrading our SCCM infrastructure to SCCM 2012 R2 after have finished with the upgrade from SCCM 2012 RTM to SP1 CU4, thus far everything works fine, but when I try to update any
of the site servers, whether CAS or Primary, I'm getting the following error message in the Prerequisites Check:
I've gone through the system requirements and prerequisites over and over again and I can assure you that every possible update, supported OS, feature set, SQL Server, check list, etc,
etc, have been followed as per the official documentation available, however I'm stuck in this point, and surely enough I haven't been able to find out a similar case.Additionally I'm adding
the ConfigMgrPrereq log (the relevant portion of it) in case someone could kindly take a look at it.
<04-25-2014 02:06:46> ******* Start Prerequisite checking. *******
<04-25-2014 02:06:47> ********************************************
<04-25-2014 02:07:00> INFO: Detected current installed build version [7711] for sitecode [BRA]. For Upgrade,
minimum supported installed build version is [7804].
<04-25-2014 02:07:00> INFPROSCCMCMS.usersad.everis.int;
Unsupported upgrade path; Error;
Configuration Manager has detected that one or more sites in the hierarchy are installed with a version of Configuration Manager that is not supported for upgrade.
<04-25-2014 02:07:00> INFO: This rule only apply to primary site, skip checking.
<04-25-2014 02:07:00> INFPROSCCMCMS.usersad.everis.int;
Active Replica MP; Passed
<04-25-2014 02:07:00> INFO: This rule only applies to primary or secondary site in hierarchy, skip checking.
<04-25-2014 02:07:00> INFPROSCCMCMS.usersad.everis.int;
Parent site replication status; Passed
<04-25-2014 02:07:00> <<<RuleCategory: Database Upgrade Requirements>>>
<04-25-2014 02:07:00> <<<CategoryDesc: Checking the target ConfigMgr database is ready to upgrade...>>>
<04-25-2014 02:07:00> ===== INFO: Prerequisite Type & Server: SQL:INFPROSCCMCDB.usersad.everis.int
=====
<04-25-2014 02:07:00> <<<RuleCategory: Access Permissions>>>
<04-25-2014 02:07:00> <<<CategoryDesc: Checking access permissions...>>>
<04-25-2014 02:07:00> INFPROSCCMCDB.usersad.everis.int;
SQL Server sysadmin rights; Passed
<04-25-2014 02:07:00> INFPROSCCMCDB.usersad.everis.int; SQL Server sysadmin rights
for reference site; Passed
<04-25-2014 02:07:00> INFO: CheckLocalSys is Admin of <INFPROSCCMCDB.usersad.everis.int>.
<04-25-2014 02:07:09> INFPROSCCMCDB.usersad.everis.int;
Site server computer account administrative rights; Passed
<04-25-2014 02:07:09> INFPROSCCMCDB.usersad.everis.int;
SQL Server security mode; Passed
<04-25-2014 02:07:09> <<<RuleCategory: System Requirements>>>
<04-25-2014 02:07:09> <<<CategoryDesc: Checking system requirements for ConfigMgr...>>>
<04-25-2014 02:07:09> INFO: OS version:601, ServicePack:1.
<04-25-2014 02:07:09> INFO: Target computer is a Windows server.
<04-25-2014 02:07:09> INFPROSCCMCDB.usersad.everis.int;
Unsupported site server operating system version for Setup; Passed
<04-25-2014 02:07:09> INFPROSCCMCDB.usersad.everis.int;
Domain membership; Passed
<04-25-2014 02:07:09> INFPROSCCMCDB.usersad.everis.int;
Pending system restart; Passed
<04-25-2014 02:07:09> <<<RuleCategory: Dependent Components>>>
<04-25-2014 02:07:09> <<<CategoryDesc: Checking dependent components for ConfigMgr...>>>
<04-25-2014 02:07:09> INFO: Return code:0, Major:10, Minor:50, BuildNum:4000
<04-25-2014 02:07:09> INFPROSCCMCDB.usersad.everis.int;
SQL Server version; Passed
<04-25-2014 02:07:09> INFO: Get Sql edition:Enterprise Edition.
<04-25-2014 02:07:09> INFPROSCCMCDB.usersad.everis.int;
SQL Server Edition; Passed
<04-25-2014 02:07:09> INFO: Checking Tcp is enabled to Static port, SQL Server:INFPROSCCMCDB.usersad.everis.int,
Instance:.
<04-25-2014 02:07:09> INFPROSCCMCDB.usersad.everis.int;
SQL Server Tcp Port; Passed
<04-25-2014 02:07:09> INFO: Checking if SQL Server memory is limited.
<04-25-2014 02:07:09> INFO: SQL Server memory is limited.
<04-25-2014 02:07:09> INFPROSCCMCDB.usersad.everis.int;
Configuration for SQL Server memory usage; Passed
<04-25-2014 02:07:09> INFO: Checking if SQL Server memory is configured to reserve minimum memory.
<04-25-2014 02:07:09> INFO: Installing the central administration site or primary site, requires SQL
Server to reserve a minimum of 8 gigabytes (GB) of memory.
<04-25-2014 02:07:09> WARN: SQL Server minimum memory is 8000 MB.
<04-25-2014 02:07:09> INFPROSCCMCDB.usersad.everis.int; SQL Server process memory allocation;
Warning; Configuration Manager requires SQL Server to reserve a minimum of 8 gigabytes (GB) of memory for the central administration site and primary site and a minimum of 4 gigabytes (GB) for the secondary site. This memory is reserved by
using the Minimum server memory setting under Server Memory Options and is configured by using SQL Server Management Studio. For more information about how to set a fixed amount of memory, see
http://go.microsoft.com/fwlink/p/?LinkId=233759.
<04-25-2014 02:07:09> INFPROSCCMCDB.usersad.everis.int;
Case-insensitive collation on SQL Server; Passed
<04-25-2014 02:07:09> INFO: Check Machine FQDN: <INFPROSCCMCDB.usersad.everis.int>.
<04-25-2014 02:07:09> INFO: getaddrinfo returned success.
<04-25-2014 02:07:09> INFPROSCCMCDB.usersad.everis.int;
Validate FQDN of SQL Server Computer; Passed
<04-25-2014 02:07:09> INFO:CheckSupportedFQDNFormat <INFPROSCCMCDB.usersad.everis.int>
<04-25-2014 02:07:09> INFO: NetBIOS <INFPROSCCMCDB>
<04-25-2014 02:07:09> INFPROSCCMCDB.usersad.everis.int;
Primary FQDN; Passed
<04-25-2014 02:07:09> <<<RuleCategory: Site Upgrade Requirements>>>
<04-25-2014 02:07:09> <<<CategoryDesc: Checking if the target ConfigMgr site is ready to upgrade...>>>
<04-25-2014 02:07:09> <<<RuleCategory: Database Upgrade Requirements>>>
<04-25-2014 02:07:09> <<<CategoryDesc: Checking the target ConfigMgr database is ready to upgrade...>>>
<04-25-2014 02:07:09> ===== INFO: Prerequisite Type & Server: SDK:INFPROSCCMCMS.usersad.everis.int
=====
<04-25-2014 02:07:09> <<<RuleCategory: Access Permissions>>>
<04-25-2014 02:07:09> <<<CategoryDesc: Checking access permissions...>>>
<04-25-2014 02:07:09> INFO: The rule 'Administrative rights on site system' has been run on server 'INFPROSCCMCMS.usersad.everis.int',
skipped.
<04-25-2014 02:07:09> <<<RuleCategory: System Requirements>>>
<04-25-2014 02:07:09> <<<CategoryDesc: Checking system requirements for ConfigMgr...>>>
<04-25-2014 02:07:09> INFO: The rule 'Unsupported site server operating system version for Setup' has
been run on server 'INFPROSCCMCMS.usersad.everis.int', skipped.
<04-25-2014 02:07:09> INFO: The rule 'Domain membership' has been run on server 'INFPROSCCMCMS.usersad.everis.int',
skipped.
<04-25-2014 02:07:09> INFO: Windows Cluster not found on INFPROSCCMCMS.usersad.everis.int.
<04-25-2014 02:07:10> INFPROSCCMCMS.usersad.everis.int;
Windows Failover Cluster; Passed
<04-25-2014 02:07:10> INFO: The rule 'Pending system restart' has been run on server 'INFPROSCCMCMS.usersad.everis.int',
skipped.
<04-25-2014 02:07:10> <<<RuleCategory: Dependent Components>>>
<04-25-2014 02:07:10> <<<CategoryDesc: Checking dependent components for ConfigMgr...>>>
<04-25-2014 02:07:10> INFPROSCCMCMS.usersad.everis.int;
Windows Deployment Tools installed; Passed
<04-25-2014 02:07:10> INFO: CheckAdkWinPeInstalled on INFPROSCCMCMS.usersad.everis.int.
<04-25-2014 02:07:10> INFPROSCCMCMS.usersad.everis.int; Windows Preinstallation Environment
installed; Passed
<04-25-2014 02:07:10> INFPROSCCMCMS.usersad.everis.int;
SMS Provider machine has same domain as site server; Passed
<04-25-2014 02:07:10> <<<RuleCategory: Site Upgrade Requirements>>>
<04-25-2014 02:07:10> <<<CategoryDesc: Checking if the target ConfigMgr site is ready to upgrade...>>>
<04-25-2014 02:07:10> <<<RuleCategory: Database Upgrade Requirements>>>
<04-25-2014 02:07:10> <<<CategoryDesc: Checking the target ConfigMgr database is ready to upgrade...>>>
<04-25-2014 02:07:10> ***************************************************
<04-25-2014 02:07:10> ******* Prerequisite checking is completed. *******
<04-25-2014 02:07:10> ******************************************<04-25-2014 02:07:10> INFO: Updating
Prerequisite checking result into the registry
<04-25-2014 02:07:10> INFO: Connecting to INFPROSCCMCMS.usersad.everis.int registry
<04-25-2014 02:07:10> INFO: Setting registry values
If you wonder whether it might be related to this error:
-2014 02:07:00> INFO: Detected current installed build version [7711] for sitecode [BRA]. For Upgrade, minimum supported installed build version is [7804].
I confirm that this one site is a secondary one that's attached to a primary site and this log is from the CAS server, I managed to tall it and delete it from that site, but still appears listed
on the CAS management console, any idea how to force the removal of a secondary site that's attached to a primary from the CAS site when it has been removed already from said primary?
I've already tried the
Preinst /DELSITE XXX command but it only works when the site to remove it's attached to the local site and certainly not from a CAS
Finally, the version, build number and everything is correct, no idea what could be the problem, does anybody know a way to bypass this or force the re-evaluation of this rules, I've got
the impression that it's being cached somehow.
Any help would be highly appreciated,
Thank you.
Marcelo Estrada MCP-MCTS-MCITP-MCSA-MCSEHello again everybody,
I've finally managed to fix this up, in the end I had to delete those entries manually from the database as Garry suggested. After this was done the upgrade has gone through as expected with no further ado and has finalized already, now moving on to the
primary sites.
If anybody out there is facing the same issue, what I did was to delete those "stubborn" records executing the following statements over the CAS database:
DELETE
FROMServerDataWHERESiteCode='XXX'
DELETE
FROMSC_SiteDefinitionWHERESiteCode='XXX'
And this is pretty much about it. I'd recommend to take a proper backup first though as best practice.
Thank you all anyways for your answers and comments,
Marcelo Estrada MCP-MCTS-MCITP-MCSA-MCSE -
SCCM 2012 What Ports Do I need to open so DMZ servers can communicate with my SCCM Server?
Hi,
What ports do I need to open in the firewall so my DMZ servers can talk to my SCCM server on the network?
Here are my steps before to make my DMZ servers talk to my SCCM server:
1. On my SCCM 2012 SP1 CU2 I have bounderies installed --> I install SCCM Client on my DMZ server with the appropriate switches --> I go back to my SCCM server to approve the server --> Works
But now my DMZ servers stops getting definition updates from my SCCM server and I was suggested that it is much easier to open ports in DMZ.
Now, could you please tell me what ports should we open to ensure two way communication among servers?
Thanks!Yes and no. It's a bit muddy at times.
For Internet based clients, putting an Internet-enabled MP in the DMZ is perfectly acceptable because Internet clients will only choose MPs enabled for Internet communication.
For systems in the DMZ, that's where it really gets muddy. There's no perfect way to accomplish this. IMO, DMZ clients should be allowed to go back to the MP/DP in the Intranet with a targeted opening in the DMZ firewall rules that allows them to only go
to the internal MP. That's a security policy question though for your organization.
Another option is to treat the clients in the DMZ as Internet only clients. This way, they will only go to the Internet MP in the DMZ. You do lose some functionality though like Remote Control.
A final way is to actually put an MP/DP in the DMZ and deal with the timeout's that happen when clients try to talk to the MP in the Intranet. Clients will try 5 times to contact that MP before giving up. They try to find a new MP at the following times
(which are not configurable):
- Every 25 hours
- WHen the client detects a network change
- When the client agent starts
Jason | http://blog.configmgrftw.com -
Hi,
I have primary SCCM 2012 SP1, SCCM database server and standalone reporting SQL server separately.
1. I am trying to enable reporting service role in which it is detecting the primary database automatically. When i enter standalone reporting SQL server with instance name and i dont know what to enter in database name. I am getting an error while verifying.
Is it possible to configure the reporting services role if the reporting SQL server is different from primary SCCM database
2. I have a proxy server as per my understanding, i need to open WSUS user port 80 or 443 to connect to microsoft website to download the patches and client to WSUS is 8531 or 8532. Is this correct. Please correct me
3. In SCCM 2012 SP1 requires computer account and installation account needs to be added as a local admin on the primary database and reporting SQL server database.
4. I have MCAFEE antivirus enabled on all the servers. So for SCCM SQL replication is it fine to allow inbound rules for 1433 and 4022 on SQL service broker or i need to create exception for 1433 and 4022 on MCAFEE antivirus
Regards, Pratap1. I got some information, i think SQL reporting person hasnt created a data source to point to site database. Because of which when i run the reporting services role it is not detecting the reporting server instance. Do we have doc on how to create a data
source. Hope this should be correct solution
2. So what happens in case if i use default website for WSUS. Which port i should open in proxy
3. But still component
/hierarchy component shows a critical error stating account doesnt have proper privelege on site system (database)
Regards, Pratap -
SCCM 2012 Application and Packages Distribution
Hi Giants,
Its Great to work with SCCM 2012 with plenty of New Features.
Let me explain my requirement.
1. Office 2010 Professional Plus SP1 with 15 Language Packs included
-----MSP 1. Without Access
-----MSP 2. With Access
-----MSP 3. With Access and Retain Old Version Access
Now My Requirement.
1. We want to deploy Office with Access to "Collection 1" and Office without Access to "Collection 2"
2. If i create Office 2010 as a Application, i can create two deployment type with different command line, but i can select the deployment type while creating Deployment. [ There should of been a drop down option like Packages. :-( ]
3. If i create Office 2010 as a Package, i cannot use the detection method or requirement rules and even i cannot publish it to Application Catalog.
Now the Scenario.
1. I can create 2 application with same source with different command line and deploy to different collection, but if i update the content in the source package, i need to give a update content to both the applications.
2. Its not a big problem to give update content to both packages, but the problem is for 1st application if i give update content, sccm will find the difference and sent the changes to DP, and when i give update content to 2nd application the same process
happens and changes are transferred to DP.
Now the Problem
1. the effort involved in transferring the changes to DP becomes twice, which means 1 GB of changes will make 2 GB transfer to DP and when adding to Content Library, SCCM is smart enough to save 1 GB.
2. Is there any where we can avoid multiple transfer to DP which will eat the bandwidth.
3. Or is there a way to define which deployment type to used in Deployment.
4. Or is there a way to publish Packages to Application Catalog.
Thanks in Advance.Hi Torsten,
Thanks for the reply.
1. if i create a single application with two different Deployment type, that is two different command line, which requirement rules i can use to differentiate them, because there is no logical separation for these command lines.
i.e. DT1. Office with Access and DT2. Office without Access.
this separation is done only for the license and is it possible to create a requirement in a way that only if this specific device in a specific collection user "With Access" or "Without Access"
2. Yes, CM12 is smart enough to save disk space with content library, but that smartness is missing while transferring the content to DP, which mean increase in Bandwidth utilization.
3. Great, i was not aware that Classic Packages can be published to Software Catalog.
Thanks Again,
SithaYuvaraj. -
GPO and SCCM 2012 Shared WSUS installation
Hello
At present I have a scenario where SCCM 2012 and wsus are installed on the same server and serving around 600 desktop clients. SCCM is configured to deploy windows updates to the client machine via the sccm client, however the member servers in the
domain do not have the sccm client installed so I have directed them to use the the WSUS installation via GPO. The servers do appear in the wsus console but never report status and never pull down any updates.
Should this setup be possible; to use one wsus instance for both sccm udpate distribution and direct communication from member servers?
windowsupdate.log entries from a member server as follows:
2014-02-04 15:10:01:172
844 1338
Agent ** START ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-02-04 15:10:01:172
844 1338
Agent *********
2014-02-04 15:10:01:172
844 1338
Agent * Online = No; Ignore download priority = No
2014-02-04 15:10:01:172
844 1338
Agent * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0
and DeploymentAction='Uninstallation' and RebootRequired=1"
2014-02-04 15:10:01:172
844 1338
Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2014-02-04 15:10:01:172
844 1338
Agent * Search Scope = {Machine}
2014-02-04 15:10:01:350
844 14d8
AU Getting featured update notifications. fIncludeDismissed = true
2014-02-04 15:10:01:351
844 14d8
AU No featured updates available.
2014-02-04 15:10:01:364
844 14d8
AU WARNING: Returning due to error from GetDownloadProgressUx, error = 0x8024000C
2014-02-04 15:10:01:364
844 14d8
AU WARNING: GetInteractiveInstallProgress failed, error = 0x8024000C
2014-02-04 15:10:01:364
564 678
WUApp WARNING: Call to GetInteractiveInstallProgress failed, hr=8024000C
2014-02-04 15:10:02:692
844 1338
Agent * Found 0 updates and 74 categories in search; evaluated appl. rules of 236 out of 825 deployed entities
2014-02-04 15:10:03:234
844 1338
Agent *********
2014-02-04 15:10:03:234
844 1338
Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdates]
2014-02-04 15:10:03:234
844 1338
Agent *************
2014-02-04 15:10:03:238
844 1be4
AU >>## RESUMED ## AU: Search for updates [CallId = {5C25CEFB-5315-4722-A422-790FBC7303B5}]
2014-02-04 15:10:03:238
844 1be4
AU # 0 updates detected
2014-02-04 15:10:03:238
844 1be4
AU #########
2014-02-04 15:10:03:238
844 1be4
AU ## END ## AU: Search for updates [CallId = {5C25CEFB-5315-4722-A422-790FBC7303B5}]
2014-02-04 15:10:03:238
844 1be4
AU #############
Thanks in advance...Should this setup be possible; to use one wsus instance for both sccm udpate distribution and direct communication from member servers?
No.
Torsten Meringer | http://www.mssccmfaq.de -
Hi
I'm trying to deploy VLC (exe file) as MSI deployment type with SCCM 2012.
The application is installed, but the detection rules (Registry) I've entered doesn't work and SCCM will try to install over and over again. (As a work around Im checking for vlc.exe in the installation folder, but would be nice to know what the issue with
the registry rules below are.)
HKEY_LOCAL_MACHINE
SOFTWARE\Wow6432Node\VideoLAN\VLC\Version
OR
HKEY_LOCAL_MACHINE
SOFTWARE\VideoLAN\VLC\Version
Value: 2.1.3
Datatype: Version
(The option This reg setting must exist... is checked)
(have also tried to just use the secound one and no OR on a 32 bit pc, but still no luck.
TonyAlso to note, if you use the VLC installer that can be downloaded from www.videolan.org, it actually opens another process that does the installation. If the detection method fails, it's probably because the actual installer process (that you've defined
to be run in the deployment type) has ended and the detection method that you've configured haven't shown up on the machine yet (because there's another process still doing the installation in the background). This can easily be seen in the AppEnforce.log.
To avoid this, you could wrap the VLC installer into a script that has a little wait time after running the installation command and use the script as your deployment type's installation command.
Maybe you are looking for
-
Creating logical standby from non primary backup
We want to test creation for logical standby in our test enviroment. Here is the plan we are 1. Backup Prod. 2. Restore Test Primary (T1) and Restore test standby (T2) from Prod backup. 3. Setup standby between T1 and T2. Plan is to save the time for
-
How to include a jsp file from other site
Hi all, I met a problem in my recent work. I need to include another seperate jsp file into my current jsp file, but the file is located at the different site (different physical server). Is there a way to include? Cheers Chris
-
A few days ago when I started my phone it automatically went into power-saving mode despite being fully charged. Instead of my newtowrk provider details being shown top left there was a message something along the lines of "ABS free version upgrade t
-
I'm not receiving any e-mail, and I'd tryed so much. Sent by 4 or 5 different e-mail's, but none came. What can be this? I've lost a proposal of job cause this. Please, give me a solution, more fast as you can. Thanks, Pablo III
-
No Subscriptions for copy of R/3 site creation in SMOEAC
Hi, I have a R/3 site in SMOEAC for replicate customers and B2C processes to ECC. And subscriptions for this Site are : BUPA_MAIN, BUPA_REL and BUS_TRANS_MSG. But now I need to transfer BUPA_MAIN and BUPA_REL from another RFC connection to ECC. I cop