How SCCM 2012 compliance function find unknown usb device

As we all know the SCCM get its own compliance DB and can monitor the all device information.
So my scenario is I want to set the USB device with known(permit) and unknown(still permit, but as the admin, I need to know who are using the unknown device).
Any one could give me some advice or procedure what should I do next ?
Asuka from ITECN

Do you want to restrict USB drives? If yes, there is a list of recently connected USB drives available in
HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
You can write a Powershell script that enumerates the subkeys there, filters out allowed USB keys (i.e. company provided encrypted ones) and puts the computer into noncompliant state if a nonapproved drive was connected.
If this is about general USB hardware, you can get the list of connected hardware with
gwmi win32_pnpentity | select Name, DeviceID
Of course, there will be thousands of different devices even in a small company, so while you could quite easily blacklist certain devices, building a whitelist will be pretty much an impossible task.

Similar Messages

  • [SCCM 2012 R2] How SCCM 2012 handles Software Update Revisions?

    Hi All,
    There are a lot of questions regarding how SCCM 2012 handles Software Update Revisions.
    Does anyone know what happened if:
    Windows update publish some update with revision #1
    Same update downloaded and deployed via SCCM 2012
    Windows update publish same update with revision #2 or any newer revision
    What is happening with SCCM and already deployed and downloaded revision? How should I know what revision is really on my distribution points?
    Thank you in advance.
    Regards,

    In WSUS Revision History is very simple:
    Where I can find revision history in SCCM??? (please do not mention dates):
    Possible scenario in SCCM:
    Windows update publish revision #1 for one update
    SCCM Download and Deploy same update and revision #1
    Windows update change revision to #2
    What SCCM does after this scenario?
    Auto update Distribution Points with new revision of already deployed and downloaded update?
    Clearly state in SCCM Console that there is new revision of already deployed and downloaded update and waiting for admin to act?
    Just update the revision in SCCM Console and leave old revision od Distribution Points?????

  • Using SCCM 2012 Compliance to check if a GPO applied

    Is it possible to use SCCM 2012 Compliance feature to check if a AD GPO settings applied to a Device / User collection or not?
    If Yes, then how?

    You can do this with SCM (Security Compliance Manager), download here:
    http://www.microsoft.com/en-us/download/details.aspx?id=16776
    Import your GPOs to SCM some guidelines here:
    http://4sysops.com/archives/microsoft-security-compliance-manager-scm-v2-part-1
    Export your GPO from SCM to DCM format guides here:
    http://blogs.msdn.com/b/scom_2012_upgrade_process__lessons_learned_during_my_upgrade_process/archive/2012/09/21/compliance-settings-sccm-2012.aspx
    Import your DCM to SCCM and off you go

  • Disk won't mount - Unknown USB Device (Link in Compliance Mode)

    I have an HP Envy DV7 (dv7-7243cl ) with Windows 8 Pro x64. My Western Digital 2 terabyte My Book USB3.0 external drive periodically won't mount ( sometimes it will, sometimes it won't). The drive has its own power source.
    When this happens Windows device manager shows - Unknown USB Device (Link in Compliance Mode). This can happen if the system is up and running and I plug the drive into the USB port or on system startup where the drive is already plugged in.
    Any clue how to fix this?
    Other details:
    Intel(R) Core(TM) i7-3630QM CPU @ 2.40GHz
    12 Gig memory
    Intel(R) HD Graphics 4000
    System board 181C 52.24
    Bios F.26

    Well, the problem is that - as outlined in one of the articles I linked to - some USB devices will not work in Safe Mode; that may have to do with the fact the Safe Mode is only meant to be a troubleshooting tool, not a regular way of booting up. Did you have the USB devices attached while upgrading to 10.6? That would also be a problem - I unplug everything except keyboard and mouse.And, did you repair permissions after the upgrade? If not, do it now.
    And, the other problem is the fact that you wait 1 - 2 years before addressing the issue; when you had it in for the last repair and it still exhibited the same problems afterwards, you should would have taken it back, possibly with some screenshots, exact notes of how/when/error messages, etc. and insisted on having it fixed or replaced.
    So, I'd run the Apple Hardware Test (after you make sure that you have a complete backup) - instructions here:
    http://support.apple.com/kb/HT1509
    Report back with whatever messages you wind up with.

  • Can anyone explain how SCCM 2012 applies its firewallpolicy.

    Can anyone explain how SCCM 2012 applies its firewall policy?
    My understanding is that it does this by altering the local policy on the client computers.
    What i am seeing though is that administrators can still change these options manually.
    But if i change the options locally sccm overides the option after a while and greys out the option so it can no longer be changed manually.
    How do i make sure that a user cannot simply open the windows firewall settings and turn of the firewall?
    Do i have to use GPO's?
    And is this working as intended?

    You're correct ConfigMgr uses local policies to manage everything, including the limited firewall options. If you really want to manage the Windows Firewall on a more detailed level you've got to look at GPO's, as they'll provide you with a lot more options.
    For an overview of the capabilities via ConfigMgr, see:
    https://technet.microsoft.com/en-us/library/hh508765.aspx
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • "Unknown USB Device"

    I got my 2GB nano last Monday. I could successfuly install it on my laptop and upload some songs to it. That done, I wrapped it again and gave it to my wife, so she and the kids could "surprise" me for my Birthday. Yesterday I got it,listened to the "sample songs that came with it", and today I tried to upload some more songs, but to no avail. Everytime I plug it in, all I get is an error message from windows, stating "Unknown USB Device". I tried everything from the iPod support site and from Windows help, but the nano simply won't be recognized. Oh, I tried to hook it up to my desktop at home as well, but nada as well. Same message.
    Is my cable fried? Is my iPod connector fried? Can someone pinpoint the problem?
    To worsen things even further, I live in Brazil, where the first nanos won't be around until Christmas, and support is but a dream...
    Help!
    Ruy

    These steps should help you with the 'Unknown USB Device' issue, Ruy:
    First, make hidden folders visible. Open My Computer and choose Tools/Folder Options/View tab. Click on 'Show hidden files and folders' and click OK.
    In the Add New Hardware Wizard, have it search in C:\windows\inf for usbstor.inf. This file is required for windows to properly configure the driver. If Windows finds the driver there, you're done.
    If Windows does not find the proper driver there, copy usbstor.sys from C:\windows\servicepack\i386 to C:\windows\system32\drivers.
    If you can't find the usbstor.inf file on your system, you can get it here: usbstor.inf
    After copying the usbstor.inf driver file to C:\Windows\inf, right-click on My Computer and choose ‘Manage.'
    Click on the button labeled 'Device Manager.'
    Click to open the list under 'Universal Serial Bus Controllers.'
    Right click on any mass storage devices with the exclamation icon next to them and select 'Update Driver.'
    Check the option 'Install from a list or a specific location' and then click to continue.
    Check next to 'Include this location in the search' and enter 'C:\windows\inf'.
    Click on 'Next' and follow the steps to complete the driver installation wizard.

  • Presario V5094EA, usb device malfunctioned, unknown usb device

    product: presario V5094EA running win XP,
    hi am having a roblem with the usb ports on my laptop they were working fine up untill two weeks ago when they just decided to stop working,
    now every time i plug something in they first find new hardware then it reports back a device has malfunctioned, unknown usb device, whether its a memory stick or my usb modem
    i have formatted the hard drive reinstalled all the drivers from the recovery discs,
    i even tried the information in an earlier post about disconnecting the battery for a period which i did for half an hour, but got the same response when i connected it all back up.
    am beginning to think this could be hardware related does any one have any ideas before i go buy a new motherboard,
    the laptop is about 6 years old now so well out of warranty,
    thanks in advance
    alan

    It should do a progress reading with percentages. If it ran all the way through and did not say anything was corrupt then I am afraid you have a hardware issue going.

  • Unknown USB Device when MuVo TX plugged in USB P

    The following message came up when I plugged in my MuVo TX in a USB Port
    Using WIndows XP
    USB attached has malfunctioned
    Windows does not recognize it
    Unknown USB Device
    Does this mean that I have a faulty player? When I first bought it on January 2 2005
    I installed approx 25 songs and it works perfect. Now that I want to change these songs
    to new ones, my MuVo TX is not recognized by Windows XP. Tried several other
    computers with same results.
    Can any one suggest a fix?
    Thanks

    If other PCs are giving the same error, then I think you can be sure the player is at fault somehow.
    Have you tried the recovery process? Download the latest driver (if required) and firmware from http://www.nomadworld.com/downloads/drivers. Install the driver file (if required). After you have installed the driver, press and hold the PLAY button, continue holding the button while inserting the player into the USB port for about 0-5 sec. Run the firmware update file and check/tick the 'Format Data Area' check box and click on 'Start'.
    If this doesn't help then I think you can be sure the player is faulty.

  • I want to download my itunes libary to my car. How do I do that via a USB device?

    I want to download mu iTunes libary to my car. How do I do that via a USB device?

    Your post is confusing.
    I have a G4 that crashed backup data on a firewire drive.
    Okay. Good thing it was only the backup. Replace the drive and back up the original data again. But this has nothing to do with iTunes.
    I want to access my iTunes playlist from an iMac
    Does this mean you have iTunes on the G4 computer and you want to access this library from the iMac?
    Turn on Home Sharing on both computers
    See this -> http://support.apple.com/kb/HT3819

  • SCCM 2012 OSD; Not finding driver package during deployment

    I've been having some trouble setting up my OSD deployment using SCCM 2012 and hope someone can point me in the right direction.  Specifically I am having trouble with device driver deployment while deploying my reference image. 
    I am running SCCM Config Manager 2012 SP1 CU2. This is running on a Server 2012 VM with SQL 2012.  I am building an OSD deployment and have successfully captured my reference image.  I am not sure if it matters, but I manually built a reference
    PC and using capture media (USB stick), I successfully captured my reference image.  I have imported my drivers for the target PC into Config Manager and into a driver package.  The driver package has been deployed to the distribution point
    (DP).  I checked the status of the driver package within the console and verified it has been deployed to the DP.   I created a new task sequence (TS) to deploy the captured wim.  Within the TS, I added an "Apply
    Driver Package" step and pointed it to the aforementioned driver package.  I added a WMI query to the step as follows
    select * from Win32_ComputerSystem where Model like "HP Probook 6570b%." 
    Incidentally, I did a wmi query on the target PC to verify the model.  I deployed the TS to the unknown computers collection and PXE booted the target PC.  I ran through the OSD wizard and while OSD is verifying the deployment prerequisites,
    the deployment fails with the error, "The task sequence cannot be run because a package referenced by the task sequence could not be found."  I checked the smsts.log log and found the following:
    Failed to find CCM_SoftwareDistribution object for AdvertID="CT120043", PackageID="CT100044", ProgramID="*"
    After some research I found this error means Config Manager cannot find the driver package (PackageID="CT100044")
    for deployment.  After more research I have done the following:
    Deleted the Driver Package and recreated it and updated the TS step to point to this package.
    Deleted and recreated the TS along with the driver package.
    Recreated the driver package and distributed content, only importing the NIC drivers as a way to make a simple test.
    When distributing content I verified it was successfully completed each time as per the console.
    Each time I recreated the driver package and the OSD failed, smsts.log is showing the appropriate package ID in the error.  If I disable the Apply Driver Package step and configure a Apply Device Drivers step to install the best matched compatible drivers
    and limit the driver matching to the specific driver package, the OSD completes but the drivers do not install. It is as if Config Manager is not seeing the imported drivers at all.
    I have run out of options to try and hope someone can help point me in the next direction to take.  After reading numerous forums and guides, I am sure I am doing the OSD steps correctly but I am apparently missing something.
    Thanks in advance,
    Mike G.

    Thanks for responding.
    Yes after I posted the question I right-clicked on the driver package, and selected to update distribution points.  I checked now (about 12 hours later) and the package is showing it has not finished updating.  I checked the content status and
    it is "waiting for content."  I looked at distmgr.log and I found an error "Failed to start DP health monitoring task for package 'CT100044'. Error code: -1".  This error would occur every 30 min after each time the DP retried to process
    the package. After some research I found a post stating a file called "Microsoft" or "Program" on located on the root of the site server could cause this and renaming or deleting the file would resolve this. I renamed the file and after the next time
    it retried, the error cleared, however the package status is still waiting for content.  I tried doing a validation on the package but so far there has been no change.

  • SCCM 2012 Compliance 7 Customize for Total Updates Needed

    I can't find single report in SCCM 2012 that lists the total count of updates needed for each computer. This really irks me and many others as this and similar info was readily available with the old WSUS console. It also takes a lot more
    clicks to get the same info in SCCM (if SCCM even has it) as it did in WSUS. Anyway, I've decided to try to customize an existing report. I made a copy of "Compliance 7 - Computers in a specific compliance state for an update group (secondary)".
    Try as I might, I can't get the query to work right to create a field for number of updates required for each computer. I'd really like columns for Failed/Needed/Applied but I'll start with just Needed. Why they got rid of this in SCCM reporting baffles me.
    I have several SQL queries that pull this info for needed patches when run in Management Studio but I can't get them to work in a SCCM Report. Does anyone know how to do this?
    Ben JohnsonWY

    I'm looking at Compliance 1, 5, and 7. The closest to what I want is Compliance 7 but with a new column for "Required Updates". I have that column made but it's not populated. I have a "Required Updates" Dataset now inside this custom
    report. BUT the row of info in the table (computer name, last logon, etc) only lets you select fields from Dataset0. Where I'm stuck is how get to the "Required_Updates" field from the "Required Updates" dataset to appear in Dataset0.
    I've spent a big chunk of time trying to get the code from the two queries merged but I can't get it to work. The other option is to somehow get the field to appear in the row's field selection list (ie, read field from both datasets).
    Oh, and when I followed your steps above, I got the report created but it throws and "error during processing" error when I run it.
    Ben JohnsonWY

  • SCCM 2012 does not find the last signature of SCEP

    Hi, we have installed SCCM 2012 with SCEP as our antivirus, all clients use the SCCM to download the signature, the alternate sources has been unmarked, and only we  have selected SCCM and WSUS to download the updates.
    In SCCM 2012 we have created the ADR to search and download ForeFront EndPoint Protection 2010 Security Updates. The server downloads the packages everyday at 01:00 a.m. (local time) and start to distribute to all DP at 03:00 a.m. The clients start to retrieve
    when they are switched on or from 08:00 a.m. and verify new signatures every hour from them.
    But the clients have the SCEP client update to 2 or 3 days ago! When we check the packages downloaded we note that the last package was not downloaded. This is the problem what we have. How can we solve this?
    Raulito

    Yes, I know this is an old post, but I’m trying to clean them up. Did you solve this problem, if so what was the solution?
    Have you confirmed that your ADR is running correctly?
    Garth Jones | My blogs: Enhansoft and
    Old Blog site | Twitter:
    @GarthMJ

  • App-V 5.0SP2 question with SCCM 2012 CU4 (functionality vs full support with R2)

    I understand that for App-V 5.0 SP2 and SCCM 2012 SP1 integration at least CU4 is required but R2 with CU1 for full functionality.
    I’ve attached an image from some session that someone else gave me. I have questions after looking at the slide since there are no details on what is not fully supported with CU4 pre R2.
    Since we have immediate plans to add CU4 to our SCCM 2012 SP1 environment can anyone please give us a break down of what functionality is not available in App-V 5.0 SP2 before we go all the way up to SCCM 2012 R2?
    On another note does anyone have any clue what TechED session that was from so I can see the replay?
    Thanks very much for any info on this.

    Hello,
    As per the slide - CU1 is required for full support with R2.
    See this article;
    http://support.microsoft.com/kb/2938441
    Application Virtualization
    This cumulative update adds support for Microsoft Application Virtualization (App-V) 5.0 Service Pack 2 (SP2). The following issues are seen only in App-V 5.0 SP2 environments earlier than CU1:
    With App-V 5.0 SP2, when a new version of an App-V package supersedes an earlier version, and when that earlier version is being used, the package is listed as not published. Errors that resemble the following are logged in the AppEnforce.log and the AppDiscovery.log
    files.
    AppEnforce.log
    Publish-AppvClientPackage : A publish operation has been scheduled, pending
    the shutdown of all applications in the package or the connection group.
    Publishing Package is successful but one one of the Virtual Package is currently in use. Close this Virtual Package to get the changes into effect
    Performing detection of app deployment type TestApp - Microsoft Application Virtualization 5(ScopeId_0C7279F0-1490-4A0E-A7A3-32A000CEF76D/DeploymentType_d1adf427-ac14-4ee1-9e51-415af7675383, revision 2) for system.
    AppDiscovery.log
    Required component [{AppVPackageRoot}]\TestApp.exe is not published
    With App-V 5.0 SP2, App-V packages that are being used cannot be uninstalled. Errors that resemble the following are logged in the AppEnforce.log file:
    CVEWorker::UninstallConnectionGroup() failed
    Nicke Källén | The Knack| Twitter:
    @Znackattack

  • SCCM 2012 Query to find units with IPv6 Enabled?

    We've found a need to locate computers that may have IPv6 enabled for audit purposes, and then we'll disable them at a later date.
    Has anyone been able to create a successful query in SCCM 2012 to get that information? 
    I found this but it spit back the IPv4 info for all the units in our device collection, plus it's for SCCM 2007. http://www.myitforum.com/forums/Query-for-systems-with-IPv6-enabled-m227020.aspx
    Appreciate any input, thanks!
    This topic first appeared in the Spiceworks Community

    If you're using % in the value field the operator must be "Like" . In your case, the query should look like
    select SMS_R_USER.ResourceID,SMS_R_USER.ResourceType,SMS_R_USER.Name,SMS_R_USER.UniqueUserName,SMS_R_USER.WindowsNTDomain from SMS_R_User where SMS_R_User.UserPrincipalName Like
    "TQA%" order by SMS_R_User.UserPrincipalName
    Kindly mark as answer/Vote as helpful if a reply from anybody helped you in this forum. Delphin

  • Unknown USB Device in Windows - VISA does not see it

    Hello,
    I'm trying to connect my STM microcontroller to my computer using USB protocol and VISA software. When I plug STM USB device into USB port Windows sees it as unknown device and can not find any driver for it. I assume that this is situation VISA was created for. So I want to use a driver wizard to create driver for this device, but VISA does not display it in a device list. I tried to create and install driver for my device as if it was not connected, and installed created driver manually but it did not work.
    Is it possible that Windows detects a USB device and VISA can't see it?

    It actually depends what sort of USB device it should be. If it is a COMM USB class device, Windows should be able to pick it up directly as serial port, if it is some proprietary USB class, then you either have to get a driver installed and access that driver somehow, or create an INF file with the VISA driver wizard for it and write the driver yourself in LabVIEW using the VISA USB Raw interface. Without a very good description of the low level USB protocol however this last option is a complete no go.
    If the VISA driver wizard doesn't display the device in the list then Windows has already claimed it somehow.
    Rolf Kalbermatter
    CIT Engineering Netherlands
    a division of Test & Measurement Solutions

Maybe you are looking for

  • Mass update of Vendor Bank Chain assignment details

    Hi Experts, I have a requirement to mass update Vendor Bank Chain  assignment details. I tried to use LSMW recording method for transaction FIBPU but it does not seems to be working if we have more than 2 bank keys for a vendor. Can you please let me

  • Macbook won't recognize password!!

    I have a Linksys Wireless-G broadband router model no. WRT54G. It has connected the main PC with another PC, but I recently got a macbook laptop, and it will not connect. It found the signal, but will not recognize my router password. Does anyone kno

  • 4 days - and still has not been activated

    I have a BT Home Hub 2.0. And my BT Total Broadband was supposed to be up on 21st Jan. I have tried everyday, but nothing. I check my settings on the gateway, and it says nothing has been activated Is this common?

  • Re-Installing CS5 Creative suite with install disk and serial#  Says serial# is bad???

    I have the install dvd and serial number.  I am trying to install after I reformatted my computer, and it is telling me that my serial number is incorrect.  ARGGGGGHHHH!!!!!  any one run into the same problem?  Any ideas?

  • Can't see any of my own music

    Hi, my husband recently got a new computer so I had got his old computer. Unfortunately when I log onto my iTunes account, all I still see is his music and can't see any of my own. How do I fix this so I can start buying more music and transfering th