SCCM 2012 Setting Windows Update GP's

Hopefully this is a simple one.
I have setup WSUS with SCCM 2012 and currently its sole purpose is for updating our WIM images however... It seems though that all of our devices that have the SCCM 2012 client installed are having their windows updates local group policy settings changed
to our distribution point and all other setting changed to not configured(overriding the settings the admins previously had in place).
I don't want the sccm client to make changes to the windows update local group policy... how can I accomplish this?  

We are using a separate WSUS server to manage updates on servers and clients.
In the near future I'll attempt to transition to the WSUS I have integrated with SCCM.
For regular client machines we're pushing the windows update GP's but for our servers the system admin are managing those themselves depending on how they want windows updates to behave on their systems.

Similar Messages

  • [SCCM 2012 R2] Windows Update Agent do not scan correctly thus SCCM has bad reports

    Hi All,
    My colleagues reported that after manual download and installation of update Office 2010 SP2 ... SCCM still do not report as Installed:
    https://support.microsoft.com/en-us/kb/2687455
    KB2687455 update on SCCM is reported as:
    Update ID: 9c5e43a3-3ae9-434d-b105-a9d7902d5f9f
    Update Title: Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition
    Test Computer:
    After investigation I found out that Windows Update Agent (verbose logging) is reporting that this update is really not installed:  Agent Update {9C5E43A3-3AE9-434D-B105-A9D7902D5F9F} is deployed for scan, and is installable. It will be reported
    as installable.
    Update KB2687455 is shown in Programs and Features/Installed Updates as installed on this computer.
    Question:
    This update is MSP (not standard update) so it cannot be queried by win32_quickfixengineering WMI class. How to query all installed updates on system (registry, API, ...)?
    How WUA query ALL installed updates?
    Thank you in advance.
    Regards,

    Hi,
    You could check the version number. The version number of Office 2010 SP2 is greater than or equal to
    14.0.7015.1000.
    The script in the blog below could get List of installed Windows / office Updates.
    http://www.blackforce.co.uk/2013/01/27/get-list-of-installed-windows-office-updates-command-line
    The sample in the following article can be used to determine if a critical security update is installed on a computer. If the update isn't installed, the user can ensure that the update is downloaded and installed. The user can also ensure that
    they are notified about the status of the installation.
    https://msdn.microsoft.com/en-us/library/windows/desktop/aa387101(v=vs.85).aspx
    Note: Microsoft provides third-party contact information to help you find technical support. This contact information may change without notice. Microsoft
    does not guarantee the accuracy of this third-party contact information.
    Best Regards,
    Joyce
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

  • [SCCM 2012 R2] How SCCM 2012 handles Software Update Revisions?

    Hi All,
    There are a lot of questions regarding how SCCM 2012 handles Software Update Revisions.
    Does anyone know what happened if:
    Windows update publish some update with revision #1
    Same update downloaded and deployed via SCCM 2012
    Windows update publish same update with revision #2 or any newer revision
    What is happening with SCCM and already deployed and downloaded revision? How should I know what revision is really on my distribution points?
    Thank you in advance.
    Regards,

    In WSUS Revision History is very simple:
    Where I can find revision history in SCCM??? (please do not mention dates):
    Possible scenario in SCCM:
    Windows update publish revision #1 for one update
    SCCM Download and Deploy same update and revision #1
    Windows update change revision to #2
    What SCCM does after this scenario?
    Auto update Distribution Points with new revision of already deployed and downloaded update?
    Clearly state in SCCM Console that there is new revision of already deployed and downloaded update and waiting for admin to act?
    Just update the revision in SCCM Console and leave old revision od Distribution Points?????

  • Prestaged OSD using SCCM 2012 SP1 windows Partition variable is not being set

    Hello All  I need some assistance with a workaround.
    I am using a presaged task sequence created from a working network / PXE deployment TS for windows 7.
    This TS sets a variable for the OS partition called "Windows" and the value is set in the Partition Disk task.
    Problem is this value is not being read from a prestaged due to the OEMMedia condition skipping this partition and format task.
    Question is how do I get it to read and or set the value for that partition?
    From what I have found on Google this was an issue in beta of MDT but was fixed in RTM.  I am not using MDT TS but I do have it installed. Any idea if this is a known issue with SCCM 2012 sp1 TS? 
    Edit: also noticed that the variable's case is different and will not let me change it.
    Variable under format is "windows"  variable under Apply OS is "Windows"  when I change them to be the same then close and reopen they revert back to the above.  Are these variables case sensitive?
    Edit: for now I have changed it from variable to next available partition.  I tested it twice so far it seems to be using the correct partition and it remains to be called the C drive.  For now this will be my solution.

    When you say "presaged task sequence created from a working network / PXE deployment TS" are you saying this is still a network boot process? Or have you done "Create Task Sequence Media"?
    Dustin Estes - MCP
    yes when i say prestaged that is using the create task sequence media then selecting prestaged.

  • SCCM 2012 CU3 / WSUS - Update files are being deleted

    We have been running this configuration since April of last year and haven't had any problems. 
    The problem is a majority of the window/security updates files in the WSUSContent folder are missing.  I have ran wsusutil /reset and it takes a day or so but it will successfully download the 80GB of missing files.  But after a few days they are
    once again missing.  We do run our EPP updates through WSUS and we have no problems with those.
    I have searched endlessly through the log files, I can see where it goes through and skips them due to being superseded. 
    Do not see any database or communication issues between SCCM and WSUS, per the wsyncmgr.log it sees the thousands of that are available from our WSUS server. 
    So, any suggestions as to what might be causing the update files to be deleted from the WSUSContent folder?
    We are running this on:
    Server 2012 / SCCM 2012 CU3 / WSUS for 2012

    So, just to make sure I understand.  Is that we should be deploying updates from the SCCM Configmgr? 
    If you want to use the integrate experience, then yes.
    but the problem is that a majority of updates are showing Downloaded = No when looking under All Software Updates
    You need to either manually initiate the download of updates or set up an Automatic Deployment Rule (ADR). Either will cause ConfigMgr to download the updates placing them into an update package (which in turn gets placed on a DP where the clients can access
    and download the updates).
    wsynclog shows the sync of the update catalog, i.e., the metadata, and not the actual update binaries.
    Jason | http://blog.configmgrftw.com

  • Prestage content no longer working after SCCM 2012 R2 CU1 update

    I run SCCM 2012 R2 CU1 on a Windows 2008 R2 server.
    I upgraded to CU1 in June, and today is the first time I've attempted to pre-stage a package since then.  After pre-staging my package and getting the content out to the target DP, I went to properties of the DP, checked the box "Enable this
    distribution point for prestage content", then hit Ok.
    Next I went to distribute the content to the DP, however after going thru the wizard, nothing changes.  There is no pending status, waiting on prestage content, that I had seen in the past when doing this task.  I can go in and run the wizard
    again, and the target DP shows up in the list, like I'd never initiated the push before.
    Normal (non-prestaged) distributions work fine.
    In troubleshooting this, I also noticed that I looking at the site status of the target DP, there are no status message entries for since I upgraded to CU1 (for that matter, none of my DP's have any entries since CU1).  I did see a similar issue like
    this in the forums
    http://social.technet.microsoft.com/Forums/en-US/9491c2b1-37e6-46e3-9bb0-c5d673490d8a/component-status-not-updating-since-upgrade-from-sccm2012-sp1-cu3-to-sccm2012-r2?forum=configmanagergeneral but I don't have a backed up stat.mgr\retry inbox, it's empty.
    I think this is related to why I can no longer prestage content, but I can't seem to find a reason for it.  The fixes for R2 CU2 don't mention my issue here either
    Anyone else seeing this?
    Tony

    Hi,
    Please check SmsAdminUI.log and Smsprov.log after you distribute the content to the DP.
    Best Regards,
    Joyce
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • SCCM 2012: configure software update point

    Hi,
    I installed WSUS, installed the software update point on Windows 2012 (for SCCM 2012) with following commands:
    Install-WindowsFeature -Name UpdateServices -IncludeManagementTools
    cd 'C:\Program Files\Update Services\Tools\'
    .\wsusutil.exe postinstall CONTENT_DIR=E:\WSUS
    Add-CMSoftwareUpdatePoint -SiteCode "PRD" -SiteSystemServerName "CM01.contoso.com" -ClientConnectionType Intranet -WsusiisPort 8530 -WsusiissslPort 8531
    Now I'm stuck. How do I configure the specific update (f.e. Windows 2012, forefront etc), download them to a certain folder?
    Please advise.
    J.
    Jan Hoedt

    It really isn't practical (or possible) to try to do an entire ConfigMgr implementation using PowerShell. I don't believe that you can choose your products using PoSH.
    You will find a full list of cmdlets here
    http://technet.microsoft.com/en-us/library/jj821831(v=sc.20).aspx
    The following cmdlets are available to configure your software update infrastructure but I'm pretty sure none of them will help you with this.
    Gerry Hampson | Blog:
    www.gerryhampsoncm.blogspot.ie | LinkedIn:
    Gerry Hampson | Twitter:
    @gerryhampson

  • Windows 2012 Server Windows Update

    Hi all,
    I have Windows 2012 Servers that take a long time to do windows update.
    All servers are not connected to the internet and I have a WSUS servers where are the 2012 servers are connected to.
    Whenever I click on Windows update. The server will sort of HANGED. Open up the windows update log and found it's trying to get the update from the internet world.
    2014-07-26 11:42:53:679
    932 7e8
    Misc WARNING: Send failed with hr = 80072ee2.
    2014-07-26 11:42:53:679
    932 7e8
    Misc WARNING: Proxy List used: <(null)> Bypass List used : <(null)> Auth Schemes used : <None>
    2014-07-26 11:42:53:679
    932 7e8
    Misc WARNING: Send request failed, hr:0x80072ee2
    2014-07-26 11:42:53:679
    932 7e8
    Misc WARNING: WinHttp: SendRequestUsingProxy failed for <http://ds.download.windowsupdate.com/v11/2/windowsupdate/redir/v6-wuredir.cab>. error 0x80072ee2
    2014-07-26 11:42:53:679
    932 7e8
    Misc WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072ee2
    2014-07-26 11:42:53:679
    932 7e8
    Misc WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072ee2
    2014-07-26 11:42:53:679
    932 7e8
    Misc WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072ee2
    I leave the W2012 Server for a while and about 15-20 mins. It will find my WSUS and get the updates accordingly..
    I am using the same policy WSUS setting on the rest of my servers and do not encounter such issue.
    Anyone know what is wrong or how can I stop the server from trying to get the update from the internet?
    Thanks!

    2014-07-26 11:42:53:679 932 7e8 Misc WARNING: WinHttp: SendRequestUsingProxy failed for <http://ds.download.windowsupdate.com/v11/2/windowsupdate/redir/v6-wuredir.cab>. error 0x80072ee2
    I don't see anything in this log snippet where this client attempted to talk to a WSUS server.
    I do see where its' trying to use Microsoft Update to selfupdate, and encountering a TIMEOUT -- as it should if it doesn't have a valid Internet connection.
    Lawrence Garvin, M.S., MCSA, MCITP:EA, MCDBA
    SolarWinds Head Geek
    Microsoft MVP - Software Packaging, Deployment & Servicing (2005-2014)
    My MVP Profile: http://mvp.microsoft.com/en-us/mvp/Lawrence%20R%20Garvin-32101
    http://www.solarwinds.com/gotmicrosoft
    The views expressed on this post are mine and do not necessarily reflect the views of SolarWinds.

  • SCCM 2012 deploy windows 7: how to manage network/server load?

     Hi,
    Hypotetically, if you would deploy Windows 7 to hundreds of pc’s at once, how could you manage that, regarding organizing the deploy, regarding network/server load? F.e. you deploy to a collection which has 500 pc’s, users can select when
    to load the OS (Windows XP, we deploy the SCCM 2012 client, they can choose when to install)
     *How can you be sure network is not overloaded?
    *Can you limit in SCCM 2012 bandwith usage?
    Please advise.
    J.
    Jan Hoedt

    You need to be as local as possible. You can host a deployment point role on a client OS such as windows 7 so you could temporarily setup one machine hosting OS images and then rebuild it last as well.
    On a 100MB LAN with DP's hosted in a datacenter (not on subnet) we get to about 75 machines building at once before we see TFTP timeouts on PXE booting due to load on the local network. I would get your build as quick as possible and then do them in increasing
    block sizes whilst monitoring the network and server load.
    To speed up builds you could...
    Build and capture to get a WIM file with most apps and updates in it.
    Change the TFTPBlockSize registry settings on the DP's (If PXE booting) to as high as it will go
    Host WIM files on your DP's with the Package share settings configured and enable the "Access content directly..." option in the Apply Operating System part of your task sequence.
    Hope this helps.
    Shaun

  • SCCM 2012: Forefront, allow updates from alternative sources

    Hi,
    I'd like to enable alternative sources for updating forefront antivirus (SCEP) on SCCM 2012.
    There is a "Disable alternate sources (such as Windows Update, Microsoft Windows Server Update Services or UNC shares) for the initial definition update on client computers" in policies but, as description mentions, this is only for
    INITIAL update.
    Please advise howto/where to activate.
    J.
    Jan Hoedt

    Hi,
    You can configure multiple definition update sources and control the order in which they are assessed and applied. This is done in the
    Configure Definition Update Sources dialog box when you create an antimalware policy.
    How to Configure Definition Updates for Endpoint Protection in Configuration Manager
    http://technet.microsoft.com/en-us/library/jj822983.aspx
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • SCCM 2012: mainteance windows?

    Hi,
    What happens when you don't set any maintenance window in SCCM 2012?
    I thought it would mean "any time is a good time" (what is our goal), is that correct?
    J.
    Jan Hoedt

    Take a look at the following article which covers Business Hours v Maintenance Windows for an explanation of the differences.
    http://blogs.technet.com/b/server-cloud/archive/2012/03/28/business-hours-vs-maintenance-windows-with-system-center-2012-configuration-manager.aspx
    Cheers
    Paul | sccmentor.wordpress.com

  • SCCM 2012 and Windows 8.1 OSD

    Dear all,
    I am planning to upgrade my current site (2012 SP1) to either SP1 CU4 or R2.  This is to support Windows 8.1 OSD
    My Question is :
    i) is it worth just upgrading to Cu4 to allow this? or would it be better to schedule the full upgrade to R2?
    from what I have read R2 is a more substantial upgrade
    thanks in advance

    I believe that it is best practice to deploy the latest version of software, unless there is a specific reason not to do so.
    You are right. The upgrade to R2 is more substantial than just applying the CU. You have to, for example, uninstall ADK 8.0 and install ADK 8.1. However you might as well do this upgrade now rather than later.
    I have described the R2 upgrade process in detail here
    http://www.gerryhampsoncm.blogspot.ie/2013/10/in-place-upgrade-sccm-2012-sp1-to-r2.html
    Gerry Hampson | Blog:
    www.gerryhampsoncm.blogspot.ie | LinkedIn:
    Gerry Hampson | Twitter:
    @gerryhampson

  • Sccm 2012 R2 Software update problem

    Hi,
    I have 3 ADR's ADRWin7-1, ADRWin7-2 and ADRWin7-3
    All three Run on Second tuesday of the month and has common Package. All three ADR's create a new group every time they run.
    Schedule :
    ADRWin7-1 Deployes patches to Phase1 collection on 2nd Tuesday
    ADRWin7-2 Deployes Patches to Phase2 collection after 7 days of 2nd Tuesday
    ADRWin7-3 Deployes Patches to Phase3 collection after 14 days of 2nd Tuesday.
    Problem :
    ADRWin7-1 works fine. PC's in Phase1 gets the patches without any problem. But Phase2 and Phase3 PC's are not getting the patches. I have moved PC from Phase1 to Phase2 collection, same problem. When in Phase1 collection it gets the patches and when moved
    to Phase2, it does not.
    Not much info from logs : (Sample logs)
    WUAHangler.log :
    Successfully completed scan. WUAHandler 8/15/2014 5:02:43 PM 1336 (0x0538)
    Scan results will include superseded updates only when they are superseded by service packs and definition updates. WUAHandler 8/15/2014 5:02:43 PM 4488 (0x1188)
    Search Criteria is ((DeploymentAction=* AND Type='Software' AND CategoryIDs contains 'BFE5B177-A086-47A0-B102-097E4FA1F807')) WUAHandler 8/15/2014 5:02:43 PM 4488 (0x1188)
    Async searching of updates using WUAgent started. WUAHandler 8/15/2014 5:02:43 PM 4488 (0x1188)
    Async searching completed. WUAHandler 8/15/2014 5:02:55 PM 3708 (0x0E7C)
    Successfully completed scan. WUAHandler 8/15/2014 5:02:56 PM 1336 (0x0538)
    Scan results will include superseded updates only when they are superseded by service packs and definition updates. WUAHandler 8/15/2014 5:02:57 PM 4548 (0x11C4)
    Search Criteria is ((DeploymentAction=* AND Type='Software' AND CategoryIDs contains 'BFE5B177-A086-47A0-B102-097E4FA1F807')) WUAHandler 8/15/2014 5:02:57 PM 4548 (0x11C4)
    Async searching of updates using WUAgent started. WUAHandler 8/15/2014 5:02:57 PM 4548 (0x11C4)
    Async searching completed. WUAHandler 8/15/2014 5:03:04 PM 2608 (0x0A30)
    Successfully completed scan. WUAHandler 8/15/2014 5:03:05 PM 968 (0x03C8)
    CWuaHandler::SetCategoriesForStateReportingExclusion called with E0789628-CE08-4437-BE74-2495B842F43B;E0789628-CE08-4437-BE74-2495B842F43B,A38C835C-2950-4E87-86CC-6911A52C34A3; for leaves and E0789628-CE08-4437-BE74-2495B842F43B,A38C835C-2950-4E87-86CC-6911A52C34A3;
    for bundles WUAHandler 8/15/2014 5:18:35 PM 4256 (0x10A0)
    UpdatesHandler.log
    Initiating updates scan for checking applicability. UpdatesHandler 8/15/2014 5:02:22 PM 1336 (0x0538)
    Initiating updates scan for checking applicability. UpdatesHandler 8/15/2014 5:02:22 PM 3388 (0x0D3C)
    Successfully initiated scan. UpdatesHandler 8/15/2014 5:02:22 PM 1336 (0x0538)
    Successfully initiated scan. UpdatesHandler 8/15/2014 5:02:22 PM 3388 (0x0D3C)
    Initiating updates scan for checking applicability. UpdatesHandler 8/15/2014 5:02:22 PM 1336 (0x0538)
    Successfully initiated scan. UpdatesHandler 8/15/2014 5:02:22 PM 1336 (0x0538)
    Initiating updates scan for checking applicability. UpdatesHandler 8/15/2014 5:02:22 PM 1336 (0x0538)
    Successfully initiated scan. UpdatesHandler 8/15/2014 5:02:22 PM 1336 (0x0538)
    Updates scan completion received, result = 0x0. UpdatesHandler 8/15/2014 5:02:41 PM 3388 (0x0D3C)
    Updates scan completion received, result = 0x0. UpdatesHandler 8/15/2014 5:02:42 PM 4488 (0x1188)
    Updates scan completion received, result = 0x0. UpdatesHandler 8/15/2014 5:02:43 PM 968 (0x03C8)
    Updates scan completion received, result = 0x0. UpdatesHandler 8/15/2014 5:02:57 PM 3388 (0x0D3C)
    Updates scan completion received, result = 0x0. UpdatesHandler 8/15/2014 5:03:06 PM 1336 (0x0538)
    UpdatesStore.log
    Update status from update (f61b102e-ce91-4086-94d0-fb199d7ce5ee) already exists, will modify existing instance. UpdatesStore 8/15/2014 5:03:06 PM 968 (0x03C8)
    Update status from update (f6a9dfd6-91f2-449f-aef9-0d7f5f801d03) already exists, will modify existing instance. UpdatesStore 8/15/2014 5:03:06 PM 968 (0x03C8)
    Update status from update (f7583494-fffa-4e41-99bc-1e4958f752f9) already exists, will modify existing instance. UpdatesStore 8/15/2014 5:03:06 PM 968 (0x03C8)
    Update status from update (f76f5a9c-8325-4256-a632-654f153704b4) already exists, will modify existing instance. UpdatesStore 8/15/2014 5:03:06 PM 968 (0x03C8)
    Update status from update (f802bfe3-9553-4542-bd1d-bdca38ff645c) already exists, will modify existing instance. UpdatesStore 8/15/2014 5:03:06 PM 968 (0x03C8)
    Update status from update (f90253be-d178-4681-8ca9-71ac186b31f6) already exists, will modify existing instance. UpdatesStore 8/15/2014 5:03:06 PM 968 (0x03C8)
    Update status from update (f92c8766-da08-4e0d-841d-1f36d3270cd3) already exists, will modify existing instance. UpdatesStore 8/15/2014 5:03:06 PM 968 (0x03C8)
    Update status from update (f9ff6d98-1a01-437e-8728-f29cb8c71b13) already exists, will modify existing instance. UpdatesStore 8/15/2014 5:03:06 PM 968 (0x03C8)
    Update status from update (fa090999-3b89-4dd1-82b2-6e16b0841e24) already exists, will modify existing instance. UpdatesStore 8/15/2014 5:03:06 PM 968 (0x03C8)
    Update status from update (fbc9a192-a1d6-4008-8ea6-cd497b8b8668) already exists, will modify existing instance. UpdatesStore 8/15/2014 5:03:06 PM 968 (0x03C8)
    Update status from update (fc7e731b-f4c9-44af-aaa8-952a614b4a64) already exists, will modify existing instance. UpdatesStore 8/15/2014 5:03:06 PM 968 (0x03C8)
    Update status from update (fca3e05e-3bc0-4291-a675-9769042c9594) already exists, will modify existing instance. UpdatesStore 8/15/2014 5:03:06 PM 968 (0x03C8)
    Update status from update (fda58512-32f3-4a5d-a5c4-05a193e037d4) already exists, will modify existing instance. UpdatesStore 8/15/2014 5:03:06 PM 968 (0x03C8)
    Update status from update (fe2139b2-00f2-4eb3-8b28-d439e762967c) already exists, will modify existing instance. UpdatesStore 8/15/2014 5:03:06 PM 968 (0x03C8)
    Update status from update (ff6cd189-1c49-4438-ac4e-34d988330e5f) already exists, will modify existing instance. UpdatesStore 8/15/2014 5:03:06 PM 968 (0x03C8)
    Update status from update (ffbb4e7e-0edc-47fe-8c02-65211d2586fb) already exists, will modify existing instance. UpdatesStore 8/15/2014 5:03:06 PM 968 (0x03C8)
    Successfully done with SetStatus() operation. UpdatesStore 8/15/2014 5:03:06 PM 968 (0x03C8)
    Querying update status of 10 updates. UpdatesStore 8/15/2014 5:03:06 PM 1336 (0x0538)
    Querying update status completed successfully. UpdatesStore 8/15/2014 5:03:06 PM 1336 (0x0538)
    Querying update status of 14 updates. UpdatesStore 8/15/2014 5:03:06 PM 4548 (0x11C4)
    Querying update status completed successfully. UpdatesStore 8/15/2014 5:03:06 PM 4548 (0x11C4)
    Querying update status of 22 updates. UpdatesStore 8/15/2014 5:03:06 PM 2372 (0x0944)
    Querying update status completed successfully. UpdatesStore 8/15/2014 5:03:06 PM 2372 (0x0944)
    Querying update status of 12 updates. UpdatesStore 8/15/2014 5:03:06 PM 4488 (0x1188)
    Querying update status completed successfully. UpdatesStore 8/15/2014 5:03:06 PM 4488 (0x1188)
    Querying update status of 26 updates. UpdatesStore 8/15/2014 5:03:06 PM 4516 (0x11A4)
    Querying update status completed successfully. UpdatesStore 8/15/2014 5:03:06 PM 4516 (0x11A4)
    Querying update status of 10 updates. UpdatesStore 8/15/2014 5:03:06 PM 4368 (0x1110)
    Querying update status completed successfully. UpdatesStore 8/15/2014 5:03:06 PM 4368 (0x1110)
    Querying update status of 12 updates. UpdatesStore 8/15/2014 5:03:06 PM 1984 (0x07C0)
    Querying update status completed successfully. UpdatesStore 8/15/2014 5:03:06 PM 1984 (0x07C0)
    Querying update status of 1 updates. UpdatesStore 8/15/2014 5:03:06 PM 4296 (0x10C8)
    Querying update status completed successfully. UpdatesStore 8/15/2014 5:03:06 PM 4296 (0x10C8)
    Querying update status of 10 updates. UpdatesStore 8/15/2014 5:03:07 PM 4516 (0x11A4)
    Querying update status completed successfully. UpdatesStore 8/15/2014 5:03:07 PM 4516 (0x11A4)
    Windowsupdate.log
    2014-08-15 17:03:03:963  924 1024 Agent   * Added update {801E75EC-F4EF-483C-B606-AB930EBF46B3}.202 to search result
    2014-08-15 17:03:03:963  924 1024 Agent   * Added update {61BFE3EC-A1DC-4EAB-9481-0D8FD7319AE8}.100 to search result
    2014-08-15 17:03:03:963  924 1024 Agent   * Added update {07D8D1ED-1E2A-4696-A20F-9EE6D983B0E6}.100 to search result
    2014-08-15 17:03:03:963  924 1024 Agent   * Added update {B0CD9CEE-4C6B-4E2D-B4DA-1F83C4657C18}.104 to search result
    2014-08-15 17:03:03:963  924 1024 Agent   * Added update {006666EF-3638-4ADC-8DA0-65F08E31A4C2}.102 to search result
    2014-08-15 17:03:03:963  924 1024 Agent   * Added update {0CFB8DEF-9B7E-478C-A746-8F9F91311DB5}.103 to search result
    2014-08-15 17:03:03:963  924 1024 Agent   * Added update {2EE7B9F1-22B7-4618-84B1-8F0804A2ED02}.101 to search result
    2014-08-15 17:03:03:963  924 1024 Agent   * Added update {99EB2EF3-7266-4488-9A80-A49418A4D1D4}.201 to search result
    2014-08-15 17:03:03:963  924 1024 Agent   * Added update {B34E43F5-2F06-4D9D-B147-EE76B076E9C0}.100 to search result
    2014-08-15 17:03:03:963  924 1024 Agent   * Added update {AD752FF8-DF05-4532-84B2-FEFF2D98F689}.101 to search result
    2014-08-15 17:03:03:963  924 1024 Agent   * Added update {5357F0F8-DC7C-467C-8D8D-EA4D6345260C}.200 to search result
    2014-08-15 17:03:03:963  924 1024 Agent   * Added update {77507BF9-6899-47DF-96D0-2FFA53A90470}.101 to search result
    2014-08-15 17:03:03:963  924 1024 Agent   * Added update {EFA1E1FA-3CAD-4098-94E7-571D00F5B3BA}.202 to search result
    2014-08-15 17:03:03:963  924 1024 Agent   * Added update {ACCDC8FE-BC27-4473-9F35-BD9D0880B4D2}.101 to search result
    2014-08-15 17:03:03:966  924 1024 Agent   * Found 192 updates and 8 categories in search; evaluated appl. rules of 313 out of 697 deployed entities
    2014-08-15 17:03:03:972  924 1024 Agent *********
    2014-08-15 17:03:03:972  924 1024 Agent **  END  **  Agent: Finding updates [CallerId = CcmExec]
    2014-08-15 17:03:03:972  924 1024 Agent *************
    2014-08-15 17:03:03:990 3536 3c8 COMAPI >>--  RESUMED  -- COMAPI: Search [ClientId = CcmExec]
    2014-08-15 17:03:04:340 3536 3c8 COMAPI   - Updates found = 192
    2014-08-15 17:03:04:340 3536 3c8 COMAPI ---------
    2014-08-15 17:03:04:340 3536 3c8 COMAPI --  END  --  COMAPI: Search [ClientId = CcmExec]
    2014-08-15 17:03:04:340 3536 3c8 COMAPI -------------
    2014-08-15 17:15:14:576  924 a98 Shutdwn user declined update at shutdown
    2014-08-15 17:15:14:576  924 a98 AU Successfully wrote event for AU health state:0
    2014-08-15 17:15:14:576  924 a98 AU AU initiates service shutdown
    2014-08-15 17:15:14:576  924 a98 AU ###########  AU: Uninitializing Automatic Updates  ###########
    2014-08-15 17:15:14:701  924 a98 Report CWERReporter finishing event handling. (00000000)
    2014-08-15 17:15:14:717  924 a98 Service *********
    2014-08-15 17:15:14:717  924 a98 Service **  END  **  Service: Service exit [Exit code = 0x240001]
    2014-08-15 17:15:14:717  924 a98 Service *************
    2014-08-15 17:18:22:445  904 230 Misc ===========  Logging initialized (build: 7.6.7600.256, tz: +0100)  ===========
    2014-08-15 17:18:22:445  904 230 Misc   = Process: C:\Windows\system32\svchost.exe
    2014-08-15 17:18:22:445  904 230 Misc   = Module: c:\windows\system32\wuaueng.dll
    2014-08-15 17:18:22:445  904 230 Service *************
    2014-08-15 17:18:22:445  904 230 Service ** START **  Service: Service startup
    2014-08-15 17:18:22:461  904 230 Service *********
    2014-08-15 17:18:23:256  904 230 Agent   * WU client version 7.6.7600.256
    2014-08-15 17:18:23:287  904 230 Agent   * Base directory: C:\Windows\SoftwareDistribution
    2014-08-15 17:18:23:428  904 230 Agent   * Access type: No proxy
    2014-08-15 17:18:23:521  904 230 Agent   * Network state: Connected
    2014-08-15 17:18:36:498  904 e54 Report CWERReporter::Init succeeded
    2014-08-15 17:18:36:514  904 e54 Agent ***********  Agent: Initializing Windows Update Agent  ***********
    2014-08-15 17:18:36:514  904 e54 Agent ***********  Agent: Initializing global settings cache  ***********
    2014-08-15 17:18:36:514  904 e54 Agent   * WSUS server:
    http://SCCMserver.com:8530
    2014-08-15 17:18:36:514  904 e54 Agent   * WSUS status server:
    http://SCCMserver.com:8530
    2014-08-15 17:18:36:514  904 e54 Agent   * Target group: (Unassigned Computers)
    2014-08-15 17:18:36:514  904 e54 Agent   * Windows Update access disabled: No
    2014-08-15 17:18:36:514  904 e54 DnldMgr Download manager restoring 0 downloads
    2014-08-15 17:18:37:886  904 230 Report ***********  Report: Initializing static reporting data  ***********
    2014-08-15 17:18:37:886  904 230 Report   * OS Version = 6.1.7600.0.0.65792
    2014-08-15 17:18:37:886  904 230 Report   * OS Product Type = 0x00000004
    2014-08-15 17:18:37:886  904 230 Report   * Computer Brand = VMware, Inc.
    2014-08-15 17:18:37:886  904 230 Report   * Computer Model = VMware Virtual Platform
    2014-08-15 17:18:37:886  904 230 Report   * Bios Revision = 6.00
    2014-08-15 17:18:37:886  904 230 Report   * Bios Name = PhoenixBIOS 4.0 Release 6.0    
    2014-08-15 17:18:37:886  904 230 Report   * Bios Release Date = 2012-07-02T00:00:00
    2014-08-15 17:18:37:886  904 230 Report   * Locale ID = 1033
    2014-08-15 17:18:43:049  904 10f4 Report CWERReporter finishing event handling. (00000000)
    2014-08-15 17:19:22:199  904 230 AU ###########  AU: Initializing Automatic Updates  ###########
    2014-08-15 17:19:22:199  904 230 AU   # WSUS server:
    http://SCCMserver.com:8530
    2014-08-15 17:19:22:199  904 230 AU   # Detection frequency: 10
    2014-08-15 17:19:22:199  904 230 AU   # Approval type: Pre-install notify (Policy)
    2014-08-15 17:19:22:199  904 230 AU   # Auto-install minor updates: Yes (Policy)
    2014-08-15 17:19:22:199  904 230 AU Successfully wrote event for AU health state:0
    2014-08-15 17:19:22:199  904 230 AU Initializing featured updates
    2014-08-15 17:19:22:199  904 230 AU Found 0 cached featured updates
    2014-08-15 17:19:22:199  904 230 AU Successfully wrote event for AU health state:0
    2014-08-15 17:19:22:199  904 230 AU Successfully wrote event for AU health state:0
    2014-08-15 17:19:22:199  904 230 AU AU finished delayed initialization
    2014-08-15 17:19:22:199  904 230 AU #############
    2014-08-15 17:19:22:199  904 230 AU ## START ##  AU: Search for updates
    2014-08-15 17:19:22:199  904 230 AU #########
    2014-08-15 17:19:22:199  904 230 AU <<## SUBMITTED ## AU: Search for updates [CallId = {081DAF36-6F30-4383-9B4F-3439B1869B38}]
    2014-08-15 17:19:22:199  904 10f4 Agent *************
    2014-08-15 17:19:22:199  904 10f4 Agent ** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2014-08-15 17:19:22:199  904 10f4 Agent *********
    2014-08-15 17:19:22:199  904 10f4 Agent   * Online = No; Ignore download priority = No
    2014-08-15 17:19:22:199  904 10f4 Agent   * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1
    or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
    2014-08-15 17:19:22:199  904 10f4 Agent   * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
    2014-08-15 17:19:22:199  904 10f4 Agent   * Search Scope = {Machine}
    2014-08-15 17:19:29:982  904 10f4 Agent   * Found 0 updates and 171 categories in search; evaluated appl. rules of 337 out of 2240 deployed entities
    2014-08-15 17:19:29:982  904 10f4 Agent *********
    2014-08-15 17:19:29:982  904 10f4 Agent **  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2014-08-15 17:19:29:982  904 10f4 Agent *************
    2014-08-15 17:19:29:998  904 10f4 Report REPORT EVENT: {CD4756C6-2116-4B99-B2AD-C970D24DE94F} 2014-08-15 17:19:22:199+0100 1 202 102 {00000000-0000-0000-0000-000000000000} 0 0 AutomaticUpdates Success Content
    Install Reboot completed.
    2014-08-15 17:19:29:998  904 1108 AU >>##  RESUMED  ## AU: Search for updates [CallId = {081DAF36-6F30-4383-9B4F-3439B1869B38}]
    2014-08-15 17:19:29:998  904 1108 AU   # 0 updates detected
    2014-08-15 17:19:30:013  904 1108 AU #########
    2014-08-15 17:19:30:013  904 1108 AU ##  END  ##  AU: Search for updates [CallId = {081DAF36-6F30-4383-9B4F-3439B1869B38}]
    2014-08-15 17:19:30:013  904 1108 AU #############
    2014-08-15 17:19:30:013  904 1108 AU Featured notifications is disabled.
    2014-08-15 17:19:30:013  904 1108 AU Successfully wrote event for AU health state:0
    2014-08-15 17:19:30:013  904 1108 AU Successfully wrote event for AU health state:0
    2014-08-15 17:19:30:029  904 10f4 Report CWERReporter finishing event handling. (00000000)
    2014-08-15 17:19:35:020  904 10f4 Report CWERReporter finishing event handling. (00000000)
    2014-08-15 17:22:35:006  904 10f4 Report Uploading 1 events using cached cookie, reporting URL =
    http://SCCMserver.com:8530/ReportingWebService/ReportingWebService.asmx
    2014-08-15 17:22:35:255  904 10f4 Report Reporter successfully uploaded 1 events.
    Not sure whats going wrong??????????
    When I checked the Deployment Monitoring Tool for the perticular test PC, the contents for the Patch deployments are blank (Have attached the image)
    Thanks.

    Let's start with that I think it's a very tricky method of deploying software updates. There is always a possibility that between phase 1 and 3 some updates are revised or even some complete new updates are available. That could cause differences (in for
    example behavior) between your test clients and your other clients.
    Back to your issue, it's hard to judge based on the log snippets. It looks like a function client and at the end I see something about 0 updates available.. Make sure that the software update group contains updates, the deployment is targeted to the right
    collection and the content is all downloaded and available.
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • AMT 3.2.10 Clients with SCCM 2012 on Windows 2012

    Hey
    I have a couple of HP dc7800 computers with Intel's AMT/vPro that I'd like to provision with SCCM 2012. The installed firmware version is 3.2.10 which is a supported version according to the documentation [1]. Provisioning of newer clients (5.2.x upwards)
    is successful, so I can rule out all the usual suspects like the provisioning certificate from GoDaddy, our internal CA, DHCP options, etc. Provisioning with SCCM 2007 of both 3.2.x and 5.x AMT devices is also still successful. 
    The amtopmgr.log repeatedly shows the following entries:
    Provision target is indicated with SMS resource id. (MachineId = 16777325 WS45.mydomain.ch)
    Found valid basic machine property for machine id = 16777325.
    Warning: Currently we don't support mutual auth. Change to TLS server auth mode.
    The provision mode for device WS45.mydomain.ch is 1.
    The IP addresses of the host WS45.mydomain.ch are x.x.x.x.
    Root hash of provisioning certificate is 2796BAE63F1801E277261BA0D77770028F20EEE4.
    Attempting to establish connection with target device using SOAP.
    Create provisionHelper with (Hash: 74B7792EDBD64EBB01E2E3A0B27FAFA04C2D3BCB)
    Set credential on provisionHelper...
    Try to use provisioning account to connect target machine WS45.mydomain.ch...
    Error 0x80090304 returned by InitializeSecurityContext during follow up TLS handshaking with server.
    **** Error 0x37f2b370 returned by ApplyControlToken
    Fail to connect and get core version of machine WS45.mydomain.ch using provisioning account #0.
    Try to use default factory account to connect target machine WS45.mydomain.ch...
    Error 0x80090304 returned by InitializeSecurityContext during follow up TLS handshaking with server.
    **** Error 0x37f2b370 returned by ApplyControlToken
    Fail to connect and get core version of machine WS45.mydomain.ch using default factory account.
    Try to use provisioned account (random generated password) to connect target machine WS45.mydomain.ch...
    Error 0x80090304 returned by InitializeSecurityContext during follow up TLS handshaking with server.
    **** Error 0x37f2b370 returned by ApplyControlToken
    Fail to connect and get core version of machine WS45.mydomain.ch using provisioned account (random generated password).
    Error: Device internal error. This may be caused by: 1. blabla...
    Error: Can NOT establish connection with target device. (MachineId = 16777325)
    After some investigation with Wireshark, I've found out that SCCM tries connect with TLSv1 to the AMT device. The response from the device is immediately an SSL alert (internal error). Using OpenSSL, I could connect to the device if I explicitly told it
    to use SSLv3. This leads me to believe that the 3.2.x firmware cannot handle TLSv1 correctly and SCCM never tries to connect with SSLv3 after a failure.
    So the question is: How can I get SCCM 2012 to provision these devices?
    Regards,
    Ingo
    [1]
    http://technet.microsoft.com/en-us/library/c1e93ef9-761f-4f60-8372-df9bf5009be0#BKMK_SupConfigOOB

    Since no one has answer this post, I recommend opening  a support case with CSS as they can work with you to solve this problem.
    Garth Jones | My blogs: Enhansoft and
    Old Blog site | Twitter:
    @GarthMJ

  • SCCM 2012 R2 CU2 Update - Need to update console or clients as well?

    Hi,
    I am going to be installing the following update onto out SCCM 2012 server:
    http://support.microsoft.com/kb/2970177/en-us
    I am not 100% sure but is there a need to update all installed consoles and/or all sccm clients after the CU2 installation?

    Site server, console and clients needs to be updated.
    Full installation guide : http://www.systemcenterdudes.com/sccm-2012-r2-cu2-installation-guide/

Maybe you are looking for