Software Update Group CLients staus Unknown

hi
We have setup sccm 2012 infrastructure  which is having cas and primary ,currently we are getting compliant reports with
Status unknown /non compliant , those machines are report 1 or 2 days before complaint ,due to machines is offline or not reachable .,management has come with request ,Legacy  wsus if a machine was complaint ,its shows complaint even systems are offline
,issue is when we check system  are complaint ,after some day it become comalaint in same SUG(software update Group)
we don't have any expired updates in group ,some machines are not sending HW ,due to machines is offline  ,so management asking already complaint machines how become non complaint ... do we have any way to save those info ,I mean the history of client
scan status in sccm 2012 ...we have put client software update scan on every 1 day ...  do we need to change the scan schedule to an extend date 
ankith

Legacy  wsus if a machine was complaint ,its shows complaint even systems are offline
So does ConfigMgr - given that the client scanned once. It will only show "unknown" for updates that were recently added if the client did not report anything back after *new* items were added to the catalog. That's expected and makes sense. 
Torsten Meringer | http://www.mssccmfaq.de

Similar Messages

  • Three updates from the same Software Update Group showing as unknown, while all the others are showing as expected.

    Hi
    I have an issue from Septembers security updates where three updates from the same software update group are showing as unknown status rather than required / not required / installed etc.
    There are multiple other updates in the same update group and they are all displaying correctly with the figures I would roughly expect.
    I would have expected if something was wrong with the clients not returning software update scans that all the updates in this software update group (all deployed automatically as part of the same ADR) would show the same status of unknown, rather than just
    three of them.
    The updates in question are: KB2894842, KB2972215 & KB2977629 (First two .net 4.0 and last one IE11).
    Now these updates would largely be not required in our organisation as for the most part we use different versions so I would expect them to show as not required.
    Short of kicking off a mass software update scan cycle I don't know a) why this has happened b) if a scan cycle will fix it. Our clients scan every week and its been several weeks since the updates were deployed, that and the other updates have all reported
    back in.
    Anyone have any ideas? Its making the compliance results look quite poor :(
    Thanks
    Jonathan

    Hi,
    Is there any clue in the logs? Please review WUAHandler.log.
    What is the code you get when you run compliance report, like that in the following thread:
    http://social.technet.microsoft.com/Forums/en-US/becda545-4a5e-4ea3-bd83-8c7026767af5/software-update-compliance-report-showing-status-unknown?forum=configmanagerdeployment

  • Software Update status stuck in Unknown Client check passed/Active

    I've been rooting around in this for a week now so I'm looking for some other ideas.
    A couple of weeks back I tried publishing some updates from SCUP into SCCM. Shortly thereafter I started seeing all my client getting stuck in Unknown "Client check passed/Active" status for Software Updates, starting with my most recent Software
    Update Groups and progressively creeping its way back into older ones.
    Clients' WUAHandler.log show errors with <![LOG[OnSearchComplete - Failed to end search job. Error = 0x8024000f.]LOG]!><time="18:16:20.329+240" date="08-14-2014" component="WUAHandler" context="" type="3"
    thread="2496" file="cwuahandler.cpp:3064">
    Client WindowsUpdate.log shows the same error code: 2014-08-15 11:37:16:278  520 1b7c Agent WARNING: WU client failed Searching for update with error 0x8024000f.
    I also have one of my older deployments starting to pick up a status of Error, code 0X8024000F "Circular update relationships were detected in the metadata."
    I found some folks with similar issues where they were advised to remove the offending updates from their packages. I never got the SCUP updates into any packages; they were showing up as Metadata Only and I started troubleshooting this issue instead. At this
    point I have removed everything from SCUP showing in SCCM console just to make sure. (I think I expired them all in SCUP and then synced with it again.)
    I have tried several client-side fixes that have not resolved the issue (KB971058, rebuild the SoftwareDistribution folder, KB947821).
    I have even uninstalled the WSUS role off my server, restarted, then reinstalled. SCCMw ill sync happily with WSUS and received this week's updates successfully but it cannot pull a status for these new updates and all the existing ones still sit in Unknown
    status in their deployments. I tried creating a new small deployment and it still gets stuck in the same place.
    It looks like my Software Updates metadata in SCCM is a mess and I'm not sure how to resolve it. I think the next step I can think of is to strip the SUP role off the server and pop it back in after its had some time to clean itself up. Does anybody have
    any other less severe suggestions?

    Hi,
    There is someone remove all the third-party metadata in WSUS Database, then run full sync and initiated scan cycle on the machine. The client successfully scanned updates.
    But editing database directly is unsupported by Microsoft.
    Best Regards,
    Joyce
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • What Changes to Software Update Group Causes Clients to Re-check Compliance

    Hello,
    I have a number of software update groups that have been deployed over the past couple of years. When Microsoft release new updates etc. some of the updates already deployed change their status e.g. an update might get marked as expired. As a result of this
    I can go from having clients reporting as being compliant to a situation where they are in an unknown state until they report back again.
    Does anyone know what changes to an update already deployed would cause clients to have to check their compliance status for that software update group?
    Thank you.
    Stephen

    If you are referring to the enforcement state, this is indeed specific to the deployment, not the group itself.
    With regards to your question - Upon a change to your deployment, your clients will receive updated policy.  On a successful evaluation of the deployment, it will re-send a state message if necessary.  Unfortunately I do not know if there are certain
    things that do not trigger a policy update (i.e. change in the name or description vs. update membership or deadline change)

  • I can not update a Windows Server 2008 R2 with Software Update Group in SCCM2012

    Hi all,
    I got some problems with update deployments these days.
    I try to configure SCCM2012 to update 1 Windows Server 2008 R2 (with Hyper-V / This server is in a cluster)
    Actually i've 4 other Hyper-V servers and i would like to add one more in the cluster called Hyper-V5. To do that i need that all Hyper-V servers use the same Windows Updates.
    I created a collection for my Hyper-V servers and then a Software Update Group with all needed updates (checked the list of another HV-Server).
    I did a deployment on this collection using this new Software Update Group.
    I checked the Sofwtare Center's logs on the Hyper-V5 server and i saw that synchronization has a successfull state.
    But there is no updates installed or displayed in Sofwtare Center.
    Here is some screenshots : Oh no i can't post image because ... "Body text cannot contain images or links until we are able to verify your account." waiting to be verified since months.
    Thanks for your help.

    Hi,
    Have you try to run Software Updates Scan Cycle and Software Updates Deployment Evaluation Cycle Actions on the client? Please check ScanAgent.log and PolicyAgent.log to see whether the client received the updates deployment policy.
    Best Regards,
    Joyce Li
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Collections based on Software Update Group compliance

    Hi!
    Is it possible to create a collection based on software update group compliance? This is for software update groups which are
    not deployed, they are just monitor groups (for example, groups for yearly or quarterly software update compliance).
    I would like to create a collection that lists all devices which are non-compliant in software update groups with names like "%Client Updates" - is this possible?
    The reason for this is so I can impose some stricter Compliance Settings (among some other stuff) on devices that are not compliant.
    I looked around a bit, but I could not find anything that I can use. Even Google couldn't solve my question :/

    you can try something like this:
    This collection is basically sub selected query get list of computers that do not have specific assignment enabled.
    select *  from  SMS_R_System where SMS_R_System.ResourceId not in (SELECT distinct SMS_UpdateComplianceStatus.MachineID  FROM SMS_UpdateComplianceStatus JOIN SMS_UpdateDeploymentSummary ON SMS_UpdateComplianceStatus.CI_ID = SMS_UpdateDeploymentSummary.CI_ID
    WHERE SMS_UpdateDeploymentSummary.AssignmentName like "%Client Updates%")
    Eswar Koneti | Configmgr blog:
    www.eskonr.com | Linkedin: Eswar Koneti
    | Twitter: Eskonr

  • Software Updates deployment remains at unknown status

    I have a curious issue where the deployment summarization is showing all required clients as "Client check passed" but they never progress and further. If I drill down into the to updates with the software update group they appear to of deployed?
    This is only effecting this one deployment there is nothing wrong with the clients it only appears to be the reporting mechanism?
    Any help appreciated.
    SCCM Deployment Technician

    Unknown means ,either that the client system did not complete the software  update scan or the site server did not receive the software update scan status from the client .You should check the logs (wuahandler.log--scan status , ,updatesdeployment.log--deployment
    ,updatestore.log--what is missing and what is installed) for further troubleshooting. you may also required to refresh the compliance state ,script avilable here https://msdn.microsoft.com/en-us/library/cc146437.aspx?f=255&MSPPError=-2147217396
    Eswar Koneti | Configmgr blog:
    www.eskonr.com | Linkedin: Eswar Koneti
    | Twitter: Eskonr

  • Downloaded additional language for software update group question

    Hi,
    We have some clients where the updates are stuck at downloading at 66% and I think it may be due to missing a language. So I went into the software update group and redownloaded it again with the additional language selected. Do I now need to do anything
    else? Do I need to re-deploy it to the collection again? Just not sure if more is required after downloading the additional language? TIA

    Correct. You can log in to any endpoint in that state and run machine policy evaluation cycle or use right click tools to do so and you should see that client download missing update.
    Additionally, you can check logs for more details on what is really going on:
    UpdatesDeployment.log UpdatesHandler.log - both in C:\Windows\CCM\Logs folder and C:\Windows\WindowsUpdate.log

  • Added additional update to software update group, do I need to deploy it?

    Hi,
    I am fairly new to SCCM and I am not sure about this. Couple days ago I downloaded some windows updates and placed them into a software update group 2015Clients and created the required deployments. So today I found an additional update that needed
    to be added to this update group 2015clients. So I downloaded the additional update and it was placed into the 2015Clients deployment package. My first question is why is it in the deployment package 2015Clients and not in the software update group 2015Clients
    as well? Second question, the new update that is now in the deployment package group says that it is not deployed like the other updates do. Do I need to deploy this new update? I was confused because when I tried to deploy it using the same deployment name
    as the other updates it wants me to use a different name. TIA

    Downloading an additional update doesn't directly add an update to an update group. Those are two separate things and by that two separate actions. There is no direct link between an update group and a deployment package.
    The deployed update group tells the client which updates it should install and the deployment package is the method to make the content of the update available.
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • Deployment Package vs Right-Click, Deploy directly from Software Update Groups?

    I'm not sure I understand the difference between collecting updates into a group and then just using right-click to create a deployment from within Software Update Groups?
    One thing I did notice this morning, is that if I want to distribute that content to other DPS, I have to create deployment package first? Are there other reasons for not simply deploying from within Software Update Groups?
    Thank-you

    Update Groups *group* updates together. That's it, they have no additional functionality.
    Updates can be deployed individually or as groups (in the form of Update Groups) -- it would be pretty painful to manually deploy every update individually so that's why there are update groups.
    Update Packages (I don't like calling them deployment packages even though that's what they're labeled as in the console because they have nothing to do with deployments) make update binaries available to the clients.
    Update Groups have nothing to do with Update Packages. Update Groups contain references to updates, update packages contain binaries. Deploying an update or update group assigns those updates to the client within the collection specified. Clients that have
    an update assigned that is also applicable will download the binary for the update from any available update package and install it.
    You create an update package by right-clicking on an update or update group and choosing download. The wizard offers you a choice between using an existing package or creating a new one. You cannot directly create on.
    Secondary sites have nothing to do with this process whatsoever. Clients are clients are clients regardless of where they are located. As long as they are within t he collection targeted by the deployment and they have access to the assigned update binaries
    in an update package, they will download and install the updates properly.
    Jason | http://blog.configmgrftw.com | @jasonsandys

  • How can I tell what Software Update Groups are members of Deployment Packages?

    I have a single SCCM 2012 SP1 CU4 server running on Windows Server 2012.
    I am trying to clean things up a little bit and I am curious:
    How can I tell which Software Update Groups use
    which Deployment Packages?  I don't see it on the Properties of either one.
    Thanks!

    Funny thing is that you can't see from the software update (in the software update group) in which deployment package(s) it exists. Your only options are manually comparing every single update (not really an option), or use PowerShell and do something
    like this:
    http://myitforum.com/myitforumwp/2014/05/12/matching-configmgr-software-updates-to-a-deployment-package-with-powershell/
    My Blog: http://www.petervanderwoude.nl/
    Follow me on twitter: pvanderwoude

  • Export and Import members of a Software Update Group

    Greetings,
    I am looking for a method I can use to Export a Software Update Group (or just it's members) to a file that I can then use to Import into another 2012 hierarchy. I can't use the built-in Migration process as it is already connected to a different Hierarchy.
    I have scripts that will pull Approvals from WSUS and then import into Update groups, but I also need something that I can use to copy update groups from "DEV" to "PROD" and back again.
    Any thought or suggestions most welcome.
    Scott.

    Hi
    You cannot export Software Update Groups in ConfigMgr 2012.
    One way of doing what you what is to use Powershell to "dump" all the settings of your Software Update Groups and then use that file as a basis for creating the Software Update Group in production. Or you could just create all Software Update Groups using
    a Powerscript which runs in dev and production.
    To get you started, you could look at the snippet of code below, which I use for creating Software Update Group automatically.
    import-module ($Env:SMS_ADMIN_UI_PATH.Substring(0,$Env:SMS_ADMIN_UI_PATH.Length-5) + '\ConfigurationManager.psd1')
    $PSD = Get-PSDrive -PSProvider CMSite
    CD "$($PSD):"
    $DPDate = get-date "22-02-2011 19:00:00"
    $SUGName = "Workstaitions 2011 02 February"
    $SUGMembers = Get-CMSoftwareUpdate | Where-Object {$_.DatePosted -eq $DPDate -and $_.NumMissing -ge 1} | select CI_ID
    New-CMSoftwareUpdateGroup -Name $SUGName -UpdateId $SUGMembers.CI_ID

  • Dots in Software Update Groups names

    Hello,
    Do you know any reason why is it impossible to put a dot (".") in a name of Software Update Group? I can use dots in SUG's name created via ADR but not when I create one manually, I receive an error: "Must specify a valid name for the software
    update group".
    How can I put dots in a names for manually created SUGs?
    SCCM 5.00.7958.1000
    http://about.me/exchange12rocks

    While you might be able to create it with an ADR or with PowerShell, if the User Interface specifically prevents it from being created, its a strong bet that it isn't tested and supported by the product team.
    You're best bet is to put in feedback on Microsoft Connect asking them to allow and support it. 
    http://myitforum.com/myitforumwp/2013/12/02/giving-feedback-on-microsoft-connect-for-configmgr-2012-help-yourself-help-the-community/
    I hope that helps,
    Nash
    Nash Pherson, Senior Systems Consultant
    Now Micro -
    My Blog Posts
    If you found a bug or want the product to work differently,
    share your feedback.
    <-- If this post was helpful, please click the up arrow or propose as answer.

  • SCCM 2012 R2 changing date and time for patching software update groups

    I recieve this error when changing date and time for software update group. worked fine yesterday before patches to the server were applied last night. we removed patches but still get error below. Any help would be great.
    ConfigMgr Error Object:
    instance of SMS_ExtendedStatus
    Description = "Property array AssignedCIs exceeded the max allowed";
    ErrorCode = 1078462259;
    File = "e:\\nts_sccm_release\\sms\\siteserver\\sdk_provider\\smsprov\\sspupdatesassignment.cpp";
    Line = 94;
    Operation = "PutInstance";
    ParameterInfo = "";
    ProviderName = "ExtnProv";
    StatusCode = 2147749889;
    Microsoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlQueryException
    The SMS Provider reported an error.
    Stack Trace:
    at Microsoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlResultObject.Put(ReportProgress progressReport)
    at Microsoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlResultObject.Put()
    at Microsoft.ConfigurationManagement.AdminConsole.SmsDialogData.Put(IResultObject resultObject, List`1 resultObjectsPut, Boolean retainLock)
    at Microsoft.ConfigurationManagement.AdminConsole.SmsDialogData.Put(Boolean retainLock)
    at Microsoft.ConfigurationManagement.AdminConsole.DialogFramework.Forms.SmsPropertySheet.Put(ActionTrigger trigger)
    System.Management.ManagementException
    Generic failure
    Stack Trace:
    at Microsoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlResultObject.Put(ReportProgress progressReport)
    at Microsoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlResultObject.Put()
    at Microsoft.ConfigurationManagement.AdminConsole.SmsDialogData.Put(IResultObject resultObject, List`1 resultObjectsPut, Boolean retainLock)
    at Microsoft.ConfigurationManagement.AdminConsole.SmsDialogData.Put(Boolean retainLock)
    at Microsoft.ConfigurationManagement.AdminConsole.DialogFramework.Forms.SmsPropertySheet.Put(ActionTrigger trigger

    no it is the final version... is working today after cleaning up database... is working now...thanks
    Hello Robert,
    would you please give some more informations, as I have the same issue and don't get what you mean bye "cleaning up databases".
    Regards ooGDoo
    ooGDoo

  • How to get a report on Installed Software Updates on client computers.

    Hi, I'm working with a large company who plans to deploy mac's nationwide. ARD is what we will be using for remote management of the cient systems. My question is; how to get a report on Installed Software Updates on client computers.
    Thanks in advance!

    Hi,
    Try this.
    Go to SE16 give table input as T511
    and select OPKEN   / Operation indicator field input as A and execute.
    This will give you output of wage types wich configured for deduction.

Maybe you are looking for

  • Weblogic Bridge Batch Size setting ?

    What is the per-requisite to set JMS bridge batch size in weblogic 10.3.3 Customer setting in production: QoS --> Exactly once Asynchronous Mode Enabled --> True Batch Size --> 1 From weblogic console "A messaging bridge instance provides transaction

  • Hi Freinds......How to Encrypt/Decrypt Text file in j2me

    Hello friendz.,, I m having problem with textfile exncryption decryption in j2me.. Can abybode tell me how to encrypt/decrypt Text file using J2ME API's....... PLZ help me ....... Thanx in advance regards, Parag

  • Problems with import and import recent

    When I click import or import recent, Premiere says it is importing, but it doesn't. The file type is MOV and it is usually something I just captured into Premiere. If I find the file and drag it to the timeline, it works fine.  Also, how can I make

  • Accessing SQL Server from Oracle

    I found an article: http:www.databasejournal.com/features/oracle/article.php/3442661 It shows how to setup a connection from Oracle to SQL Server. I am new to Oracle Using SQL Loader and PL/SQL. I would like to use the SQL Loader in Oracle to load a

  • Nokia N80 Very slow? What's up with it?

    Is anyone else haveing the same problem with the OS on the N80-1 being painfully slow? Turning on the N80, it takes about 20-30 to start up. Navigating around the menu system is like using an old megadrive, things pop up as they are loaded, it's as i