SCCM 2012 R2 - Maintenance Windows - a few questions

Let's say I configure a maintenance windows (MW) for the 2nd saturday of every month from 6p-10p and I have 100 servers in this maintenance window,
are they all going to try and patch and reboot at the same time?
(Assuming they are all online)
This brings up concerns when trying to plan maintenance windows for our servers - especially when we are 80%+ virtualized. I can't find anything that states the sequence of events that happen when a machine goes to install patches based on a MW.
Do they wait on a heartbeat? Do they typically kick off right at the front of the MW? Does SCCM spread the installs out?
We currently use WSUS (working on migrating to SCCM) and in WSUS we have a ton of groups based on the hour so we spread out the machines being patched. I am trying to avoid having so many different options and times and instead just using MWs.
Another issue we are going to run into is certain machines need to be patched/rebooted in a certain order and with others we just cant have them all down at the same time (e.g. domain controllers). I supposed I could create 2-3 phases per patch weekend to
spread those machines out - is that the best option? (for instance; on the 2nd Saturday we have MW Phase 1 from 6p-8, MW Phase 2 from 8-10, and MW Phase 3 from 10-midnight)

Let's say I configure a maintenance windows (MW) for the 2nd saturday of every month from 6p-10p and I have 100 servers in this maintenance window,
are they all going to try and patch and reboot at the same time?
(Assuming they are all online)
This brings up concerns when trying to plan maintenance windows for our servers - especially when we are 80%+ virtualized. I can't find anything that states the sequence of events that happen when a machine goes to install patches based on a MW.
Do they wait on a heartbeat? Do they typically kick off right at the front of the MW? Does SCCM spread the installs out?
We currently use WSUS (working on migrating to SCCM) and in WSUS we have a ton of groups based on the hour so we spread out the machines being patched. I am trying to avoid having so many different options and times and instead just using MWs.
Another issue we are going to run into is certain machines need to be patched/rebooted in a certain order and with others we just cant have them all down at the same time (e.g. domain controllers). I supposed I could create 2-3 phases per patch weekend to
spread those machines out - is that the best option? (for instance; on the 2nd Saturday we have MW Phase 1 from 6p-8, MW Phase 2 from 8-10, and MW Phase 3 from 10-midnight)
Hi,
I often help customers with this scenario that you are facing. I'll try to answer your questions as clearly as possible.
A) Yes, if you have 100 servers in one MW during 6p-10p, they will start at 6p if they have recieved the policy before that. What you can do is to activate the Deadline randomization that was introduced in ConfigMgr 2012 SP1. You can read more on that here
http://technet.microsoft.com/en-us/library/gg682067.aspx
B) ConfigMgr does not wait for a heartbeat or anything like that. You need to manage to logic to move your workload from hosts before you take them down for a reboot. VMM could help you with this IIRC. Or at least SCSM SMA and PowerShell. The sequence is
basically that they install the patches, if a reboot is required, it will reboot at the end of the patches.
C) Yes you need to create different MWs and place those servers in the MW order that they need to be rebooted. Be careful tough. If you have ServerA, ServerB and ServerC that need to reboot in that order. You place them in MWs in that order. You might end
up getting patches to some or all of those servers from a Patch Tuesday but perhaps only ServerB will need a reboot so only ServerB will reboot and thus put you in a place you don't want to be. To solve this, create a re-running package/program deployment
that reboots ALL servers that are sensitive each and EVERY MW.
Tim Nilimaa | Blog: http://infoworks.tv | Twitter: @timnilimaa

Similar Messages

  • SCCM 2012 R2 - Maintenance Windows + Installation deadline ASAP + Deadline Randomization

    There are a ton of questions out there regarding MWs and deadlines etc, but I haven't found any yet with my specific question:
    If I:
    Use an ADR that sets the software available time and installation
    deadline both to ASAP 
    AND
    put my machines into maintenance windows
    AND
    enabled deadline randomization (disabled by default in SP1 and R2)
    Will the deadline randomization take place during the maintenance window?
    I know the default setting for the randomization is 0-120 minutes so if I match that and make my MW 2 hours, can I expect all the machines in that MW to patch ONLY during the MW but at a random time during those 2 hrs?

    I tried for a couple days and could not get any of my 3 test machines to patch during the maintenance window with deadline randomization enabled.
    Yesterday I disabled it and over the night, 2 of my 3 machines patched during the MW.
    It doesn't appear to like the proposed setup - I would have anticipated them patching during the MW but during a random time between 0-120 min from when the MW started

  • SCCM 2012 complete maintenance

    Hi
    I am in need of SCCM 2012 complete maintenance task Manual as well as Scheduled maintenance task document. Moreover the
    link for SQL 2008 maintenance task document. If anybody is having the link for these please let me know it would be very helpful for me.I will be very thankful for this.
    Please let me know some link on below topics also.
    How to check Distribution Manager issues , Clean Configuration Manager inboxes on sites , Intermittent Proxy Management Point connection issues to SQL , Make site settings consistent between Primary sites
    Thanks in advance!!!!!!!!!!!!!!!!!
    Regards
    Gokulnath

    Hi,
    The following KB talks about Maintenance tasks default settings in SCCM 2012.
    Maintenance tasks default settings in System Center 2012 and System Center 2012 R2 Configuration Manager
    For SQL 2008 R2,
    Maintenance Tasks
    Best Regards,
    Joyce Li
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Wifi profiles SCCM 2012 R2 and Windows Intune

    Hi All,
    A quick question regarding SCCM 2012 R2 and the new Wifi Profiles feature...
    Can anyone confirm if you need windows Intune combined with SCCM 2012 R2 to be able to deploy WIFI profiles to users devices i.e Windows 8.1, IOS and Android platforms?  Microsoft documentation is not clear on this subject.
    Any help would be much appreciated.
    Regards PowerShell90

    It not as straight forward as one would hope. I am running the latest version of SCCM 2012 R2 CU2 connected to my Windows Intune subscription. There are a lot of hickups. One is that the direct of management needs to be all or nothing. In other words you
    either need to use Windows Intune solely to manage your devices or SCCM 2012 R2 (via connector). If the later then you must do everything from in SCCM 2012 R2. You cannot hybrid manage your devices as this will screw things up.
    Android for some reason is left out on a lot of features. I would think that MS Devs would work hard on the market share that being Android, not iOS. Any way, accord to some official MS articles Android is supported, but others claim that not all features
    are, these being the important ones like Email and Wi-Fi Profiles. They simply do not work.
    I think MS is heading in the right direction but there is a lot of work that needs to be done before this is a competitive product. I could care less if connects to my SCCM 2012 R2 server or not. Here are few things that I sent o a MS Support Rep today that
    need to be address.
    1. Better response time when updating devices after enrollment (e.g. Name change).
    2. The ability to locked down uninstalling Windows Intune from device.<o:p></o:p>
    3. The ability to locked down certain features in the Windows Intune app on device (e.g. User can reset device with Windows Intune app, rename, etc...).<o:p></o:p>
    4. Ability to rename device in either Windows Intune Admin Portal and/or SCCM 2-12 R2.<o:p></o:p>

  • SCCM 2012 R2 and Windows 8.1

    Hi,
    I have installed SCCM 2012 R2. SCCM client deployed on 10 PCs and I can explore Hardware resources on all PCs except 1 PC which is 8.1
    so my question now does SCCM 2012 R2 supports 8.1?
    Thanks,
    Kareem Behery

    Hi,
    Yes, ConfigMgr 2012 R2 supports Windows 8.1. Check the Windows 8.1 computer to make sure that the SCCM client is operational and sends in Inventory to the Site server. Inventpryagent.log file on the computer is a good place to start.
    Regards,
    Jörgen
    -- My System Center blog ccmexec.com -- Twitter
    @ccmexec

  • SCCM 2012 R2 and windows 7 folder redirection

    Hello gurus
    I want to ask a quick question. Does anyone know if I can do folder redirection, offline folders, roaming profiles and network drive on Windows 7 using SCCM 2012 R2?
    Thanks in advance. 
    Regards,

    The setting does not apply to Windows 7. I tested and DCMagent just thought it is Non-applicable.
    Juke Chou
    TechNet Community Support

  • SCCM 2012 SP1 Maintenance -- Random Environments Rebooting Early

    Background on my deployment process for SCCM 2012 SP1:  I run a Powershell script that sends out a package and configures settings exactly the same for the particular environment set. 
    The deployment script will call one or several environments at a time, as applicable. 
    It will take each environment, affix the settings, push the package to be deployed (based on OS) during the specified maintenance window, and repeat. It is a very consistent process.
    Last week, I deployed to A-CLOUD (name changed for simplicity purposes), among others. 
    A-CLOUD went through the same process as the others in the script (see end of paragraph), in which the appropriate settings were checked. 
    The environment was supposed to update and reboot on Saturday, July 12. 
    However, A-CLOUD (only) updated and bounced as soon as I sent out the package on Wednesday, July 9. 
    Also in the same deployment script was B-CLOUD, C-CLOUD, D-CLOUD, and E-CLOUD, which all updated and rebooted as planned on July 12.
    I received an alert that A-CLOUD was rebooted by Configuration Manager.  I checked the reboot logs in Task Scheduler to compare A-CLOUD with C-CLOUD days later to compare a faulty reboot with one that ran correctly
    (both of these environments are on the same site).  There was no difference in the log files. 
    This issue occurs at least one a month and I have only noticed ONE pattern, Server 2008R2 -- however, it is not always the same environment that will reboot early each month, same week, same day, etc.  It seems to be
    random.
    Any ideas?

    This is way too generic to be answered. What ConfigMgr object type are you deploying (package? application?)? How is the reboot initiated? How are the deployment settings etc.?
    Torsten Meringer | http://www.mssccmfaq.de

  • IIS Admin Service Disabled on all SCCM 2012 Distribution Points Automatically After few Hours

    Hi !
    Internet Information Services (IIS) is getting Disabled automatically on all of our SCCM 2012 Distribution Points after few Hours.
    Please help and share configuration steps.
    Thank you.
    Regards,
    Faisal Alvi
    Regards, Faisal Alvi PPL

    That's not something ConfigMgr does. Examine eventlog and see if there are GPOs or whatever is disabling it.
    Torsten Meringer | http://www.mssccmfaq.de

  • Microsoft Intune and SCCM 2012 R2 Integration - Windows 7 clients.

    Hi All,
    This is our scenario I am trying to find out more about Intune integration with SCCM 2012 R2 and what solution is best for us.
    We have a SCCM 2012 R2 instance up and running which services/monitors machines on our internal network. All of these machines are Windows 7 OS. We have laptops that travel frequently and need for these to report back to our SCCM server whilst connected
    via internet connections. Also we have multiple "off domain" machines (ie workgroup machines) which we also need to report back to the same SCCM server.
    I have read a lot about Intune integration with SCCM but it appears to be targetted at MDM not around PC management.
    What would be the best way for us to move forward?
    Thanks in advance.

    Just see my reply in the ConfigMgr forums. 
    Torsten Meringer | http://www.mssccmfaq.de

  • SCCM 2012, Intune and Windows OS Support

    I am just trying to confirm what I believe I am reading about Microsoft OS Support for Windows Intune when integrated with SCCM 2012 R2...
    What I believe to be the case:
    Windows RT, Windows RT 8.1, Windows 8.1 all have the ability to enroll via OMA-DM, thus can be managed by SCCM.
    Down-level OS's such as XP SP3, Vista, and Windows 7 require the Intune Client to be installed, thus can only be managed by a standalone Intune subscription?
    Can anyone confirm this?
    Thanks!

    More or less correct.
    Generally, even for Win 8.1 and WinRT, IBCM or DirectAccess are a better choice than OMA-DM as it can only enable management of a limited subset of features. Two important ones cannot be: software updates and endpoint protection.
    As you've seen (based on your other thread), you can still use the Intune subscription that is connected to your ConfigMgr site to manage devices with the Intune client installed. Effectively, there are two halves of the Intune subscription, the full client
    management half and MDM half which can be controlled by Intune or ConfigMgr. Just because the MDM half is controlled by ConfigMgr does not technically preclude you from still utilizing the full client management half. That's not at all saying you should do
    this though, but you certainly could.
    Jason | http://blog.configmgrftw.com

  • SCCM 2012: hotfixes via Windows updates?

    Hi,i
    Is this still the proper way to deploy hotfixes via Windows updates in SCCM 2012 R2 (the article is more then a year old, maybe SCCM has other built in features to do this)?
    http://blogs.technet.com/b/michaelgriswold/archive/2013/03/13/kb2775511-deployment-for-the-sccm-admin.aspx
    Please advise.
    J.
    Jan Hoedt

    Hi,
    As long as the hotfix is available in the Microsoft Update Catalog which not all hotfixes are, then it will work. It is not really supported to deploy it that way. Otherwise it is possible to deploy them using a package/program which is the way I normally
    does it.
    Here is an example of a script to use.
    http://ccmexec.com/2012/02/installing-multiple-windows-7-hotfixes-msu-with-sccm/
    Regards,
    Jörgen
    -- My System Center blog ccmexec.com -- Twitter
    @ccmexec

  • SCCM 2012 R2: OSD Windows 7 Bitlocker pre-provisioning

    Hi,
    I succesfully configure bitlocker for Dell laptops during our W7 task sequence (thanks to this guide: http://www.windows-noob.com/forums/index.php?/topic/3875-customising-windows-7-deployments-part-5/)
    Now I want to do the same for HP, found this link http://www.sccm.biz/2012/06/sccm-and-bitlocker-tpm-real-life.html but it seems a config for AFTER installing Windows, not in WINPE.
    During the TS, OS reboots and then says "no OS found", so I'd need to enable the TPM/bitlocker differently.
    Please advise (enabling bitlocker in TS, WINPE phase (pre-provision bitocker) for HP models).
    J.
    Jan Hoedt

    Hi,
    The pre-provisioning is the same for all vendors, it is the TPM part that is different from Vendor to Vendor so you can use these steps to enable TPM in the beggining och the Task Sequence and then let the pre-provisiong step enable bitlocker.
    Regards,
    jörgen
    -- My System Center blog ccmexec.com -- Twitter
    @ccmexec

  • Windows 8.1 mobile device management using integrated environment of SCCM 2012 R2 and Windows intune

    Can we avoid the dependency on the Symantec certificate  for enabling windows phone enrollment under Administration->Cloud services -> Windows InTune subscriptions - Windows Phones. My environment will have only windows 8.1 phones.
    Regards
    Leela

    See http://status.manage.microsoft.com/StatusPage/ServiceDashboard. 
    Engineers are investigating a service issue impacting access to portal via mobile devices.
    (Started on 12/30/2014 8:00:00 AM UTC)
    1/8/2015 11:42:49 PM (UTC)
    Current Status: Engineers are continuing to troubleshoot potential issues related to Active Directory Federation Services (ADFS). Engineers have gathered additional traces and logging data for deeper analysis. User Experience: Affected users with Windows Phone,
    iOS, or Android devices are unable to access their company portal and receive repeated prompts to enter credentials. If incorrect credentials are entered, users will receive an error stating that they have entered a bad password. Customer Impact: Engineers
    have received reports that some customers are experiencing this issue. A subset of users are affected by this event. Other users remain unaffected. Incident Start Time: Tuesday, December 30, 2014, at 8:00 AM UTC Next Update by: Tuesday, January 13, 2015, at
    12:00 AM UTC
    Torsten Meringer | http://www.mssccmfaq.de

  • SCCM 2012 PXE erro windows failed to start. A required device isn't connected or can't be accessed.

    I'd have an issue with the below PXE Log. I have checked the PXE boot.wim and it all checks out with 6.2.9200.16384.
    Would appreciate some insights .
    Client lookup reply: <ClientIDReply><Identification Unknown="0" ItemKey="16777848" ServerName="" ServerRemoteName=""><Machine><ClientID/><NetbiosName/></Machine></Identification></ClientIDReply>
     SMSPXE 21/08/2014 8:38:45 PM 6852 (0x1AC4)
    00:23:24:11:7B:25, F0D460E2-89A9-11DF-BBDA-24117B250023: device is in the database. SMSPXE 21/08/2014 8:38:45 PM 6852 (0x1AC4)
    Client boot action reply: <ClientIDReply><Identification Unknown="0" ItemKey="16777848" ServerName="" ServerRemoteName=""><Machine><ClientID>GUID:35AA835A-E5D6-4D68-A989-86728CCB60D4</ClientID><NetbiosName/></Machine></Identification><PXEBootAction
    LastPXEAdvertisementID="" LastPXEAdvertisementTime="" OfferID="00120018" OfferIDTime="21/08/2014 7:07:00 PM" PkgID="00100035" PackageVersion="" PackagePath="http://srv-01/SMS_DP_SMSPKG$/001000005"
    BootImageID="00100005" Mandatory="0"/></ClientIDReply>
     SMSPXE 21/08/2014 8:38:45 PM 6852 (0x1AC4)
    00:23:24:11:7B:25, F0D460E2-89A9-11DF-BBDA-24117B250023: found optional advertisement 00120018 SMSPXE 21/08/2014 8:38:45 PM 6852 (0x1AC4)
    Looking for bootImage 00100005 SMSPXE 21/08/2014 8:38:45 PM 6852 (0x1AC4)

    Hi,
    Could you please upload the log to OneDrive ?
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • SCCM 2012 Maintenance Task

    Hi
    I am in need of SCCM 2012 complete maintenance task Manual as well as Scheduled maintenance task document. Moreover the
    link for SQL 2008 maintenance task document. If anybody is having the link for these please let me know it would be very helpful for me.I will be very thankful for this.
    Please let me know some link on below topics also.
    How to check Distribution Manager issues , Clean Configuration Manager inboxes on sites , Intermittent Proxy Management Point connection issues to SQL , Make site settings consistent between Primary sites
    Thanks in advance!!!!!!!!!!!!!!!!!
    Regards
    Gokulnath

    Duplicate post of
    http://social.technet.microsoft.com/Forums/en-US/189e9afe-17e0-4a35-9777-3c20a102960a/sccm-2012-complete-maintenance?forum=configmanagergeneral
    http://www.enhansoft.com/

Maybe you are looking for

  • In migo 545 mov type is occuring instead of 543(Subcontracting Process)

    Hi All Subcontracting scenario is there Movement type as per declaration. 201-- Some material is issued. 262-- one material is reversed. 541--Transfered to Sub con(Same reversed mat is included here) 101--Migo is done after comming back from vendor(S

  • Car with USB input - but music plays from phone sp...

    Hi all, Last week I got a new Nokia Lumia 520. I've had iPhones for years, but since getting an iPad, though I'd have a change of phone. Our Nissan Quasquai has a usb input which connects straigh to the head unit. I can plug my iPad straight into tha

  • Have installed SAP webAS 6.2

    hello, I have installed a CD named SAP WEB AS Rel.6.2. And I dont know whethear it is WEBAS or not. Infact It has loaded SAP J2EE engine. Is this SAP J2EE Engine is SAP WebAS? Please let us know whethear both are same or not? And also let me know how

  • Traverse a binary tree from root to every branch

    I have a couple of other questions. I need to get all the different combinations of a binary tree and store them into a data structure. For the example in the code below, the combinations would be: 1) Start, A1, A2, A3, B1, B2, B3 2) Start, A1, A2, B

  • Date to Calendar Week in Update Rules

    Hi Experts, Does anyone of you know how/where BI/BW do the mapping when translating date in to a week in update rules? Thanks in advance, Rose