Quantcast
Channel: Configuration Manager 2007 Software Updates Management forum
Viewing all 700 articles
Browse latest View live

SCCM Query to list machines that are not compliant to a specific Update List?

$
0
0

Hello,

I have been trying to create a Collection-based Query that collects all machines which are not compliant with a specific Update List. I have looked everywhere for some information about an Attribute that relates to Update List without any luck....

Im thinking one of the Attributes under Software Updates class must be the answer. Since i can draw a report that shows AuthListID with a value of ScopeId_xXxxx/AuthList_xxxxx, there must be a related attribute somewhere to add in a collection-based query. Has anyone successfully done this? Any related information would be very much appreciated.


Scan failed with error = 0x8007000e

$
0
0

Hi,

i am unable to update patch, please help me on the same.

Its a WSUS Update Source type ({D4A9F44D-0E23-484C-9F4C-52F5DA685015}), adding it. WUAHandler 5/23/2012 12:56:10 AM 8984 (0x2318)
Existing WUA Managed server was already set (http://servername:80), skipping Group Policy registration. WUAHandler 5/23/2012 12:56:10 AM 8984 (0x2318)
Added Update Source ({D4A9F44D-0E23-484C-9F4C-52F5DA685015}) of content type: 2 WUAHandler 5/23/2012 12:56:10 AM 8984 (0x2318)
Async searching of updates using WUAgent started. WUAHandler 5/23/2012 12:56:10 AM 8984 (0x2318)
Async searching completed. WUAHandler 5/23/2012 12:56:14 AM 6932 (0x1B14)
OnSearchComplete - Failed to end search job. Error = 0x8007000e. WUAHandler 5/23/2012 12:56:14 AM 8984 (0x2318)
Scan failed with error = 0x8007000e. WUAHandler 5/23/2012 12:56:14 AM 8984 (0x2318)

Thank you.

Adding updates to an existing deployment causes clients to get stuck at downloading

$
0
0

Hello all. Sometimes MS will revise or release a patch a few days after Patch Tuesday to address an issue (ex: KB3033395, March 2015). In these cases I simply download the revised update to a package, and then add the update (drag and drop) to the existing deployment. This has worked in the past, but suddenly this week I have ran into the issue a few times.

I can't find any obvious errors in the client log files:

UpdatesDeployment.log: Assignment({19EBE7A1-40A4-451E-B1E0-50BE958482A4}) already in progress state (AssignmentStateDownloading). No need to evaluateUpdatesDeploymentAgent3/17/2015 11:02:38 AM624 (0x0270)

UpdatesHandler.log: Bundle update (f5bcf591-1b57-4904-bbd0-0df0ba9410b0) is requesting download from child updates for action (INSTALL) CAS.log: Location update from CTM for content 530ff762-1806-4601-aae5-d83d83d89e01.1 and request {4F338AA7-9C94-4064-99A8-6CA9E0B9C3F5} Download request only, ignoring location updatThe Updates UI is not displayed

The Updates UI is not displayed on the client, the only indication something is wrong is in the log files and reports. 

Any suggestions on where else I could look for the problem?

Thanks!

SCCM 2012 R2 - Software deployment

$
0
0

Hi All, 

In our organisation the definition of compliance is if at least one update is installed on a machine for that month than it is compliant for us. Is there any default report or prepare a report that will tell us that at least one software update is installed on each of the machine and hence is compliant. 

Regards,

Preliminary Success and office patches

$
0
0

Background:

1.  99.7% of our clients have installed KB2880971 - 10's of thousands of clients

3.  the clients that do not show it as installed show all other patches install verified, except

4.  some MS Office patches (not all) show as Preliminary Success, non-compliant and are required

5.  the patches show as installed in add remove programs

6.  the clients are running scans just fine, have rebooted many times, and otherwise appear healthy

7.  I ran the update compliance script and updatesStore.log still shows that patch as missing

Since this specific patch should have installed last year, all logs from that time have wrapped.  I don't see any errors.  Why are some MS Office patches showing as preliminary success, non-compliant in SCCM, when they appear in fact to have been installed?  They have installed since they're in Add\Remove Programs, right?  What can be done about this? 

SCCM 2007 - Software Update Large Package error " Package xxxxxx requires a newer version (1) of source files and the new compressed files haven't arrived yet, current version is 0, skip D:\Program Files (x86)\Microsoft Configuration Manager\inboxes\....

$
0
0

Hi

We have Primary Site server and few secondary site server. we are deploying the software Update to all the secondaries DP locations.

Issue: we have update package about 890 MB it is deployed to few of the DP's but other DP we are getting following problem in the logs " Package xxxxxx requires a newer version (1) of source files and the new compressed files haven't arrived yet, current version is 0, skip D:\Program Files (x86)\Microsoft Configuration Manager\inboxes\distmgr.box\INCOMING"

Removing package ROT000ED from the active package array.  $$<SMS_DISTRIBUTION_MANAGER><Tue Mar 31 09:33:29.369 2015 India Standard Time><thread=10128 (0x2790)>

I got the suggestion to do the Prestage but whether it is applicable for Software Updates packages also please confirm or give the steps to do the same.

Error State Id 11756 and Client side Scan Agent.log file shows with Error=0x8024400d

$
0
0

We 1500 clients which managed through SCCM 2007. out of 1500 workstations 300 are showing failed to install updates with following error code from scanagent.log. Also the error state messge id is 11756
 -Scan Failed for ToolUniqueID={CACC0F54-E6B6-40AA-8BCD-81A1C7BE2918}, with Error=0x8024400d

Error From WUAHanlder.log

OnSearchComplete - Failed to end search job. Error = 0x8024400d.

I searched over google for this issue and found some thing related with Group policy, but there is no exact cause and solution found for this. Could you please some one help me on this.

Software Updates failed to installed on Server 2008 R2

$
0
0

Hello All,

I have performed deployment of around 89 software updates on Windows Server 2008 Citrix Terminal Server. However, out of them only 1 of them got installed .  8 updates got downloaded in ccmcache.

The updates were installing manually if we try to install them.

I do not understand why this happened.

I have checked the "States 3 - States for a deployment and computer" and appears that Software updates are not required. Also, i of list of few updates which listed as "is installed", but actually does not appears to be installed.

Please share your valuable inputs.


View task sequence progress?

$
0
0

hey all,

i recently pushed a task sequence advertisement, and want to view its progress and make changes to the advertisement (i'm also making the assumption that it's active until removed).

i've been using the 'Status summary of a specific task sequence advertisement' report, is there any other way to view the status of the advertisement?

i also need to make a change to the advertisement, and eventually remove it; where can this be done?

any help is greatly appreciated.

thanks!

Apply only certain updates to a certain collection

$
0
0

We are running SCCM 2007 R3 with update point configured. Our SCCM admin has recently left so I have to apply few updates as per requirements from security department.

I want to apply only certain windows updates to a certain collection of computers and disable application of any other updates to any other computer.

Can someone guide me or tell me links which discuss this sort of configuration.

Thanks

Deployment Packages Empty, WSUS syncs fine

$
0
0

Hello everyone

I have a 2007 r2 SCCM and 3.0 WSUS environment.  I am trying to troubleshoot why my deployment packages are empty.

Looking at WSUS content folder, I have nearly 15 GB of data in there that appears to be all of the update information required.  However when I attempt to Download the updates through SCCM from the internet, SCCM attempts to download, appears to show that it is finished but each update says "Unable to contact server - timeout".   Now I know this server can access the internet since WSUS has no problems connecting to Microsoft Updates.  

Is the server being contacted the WSUS server?  I downloaded the superflows on this but it really wasnt clear to me.  if the server being contacted is Microsoft Update, then there really should be no reason why there is a communication issue since the Proxy is set up through SCCM and WSUS uses that info to contact Microsoft Update.

What ends up is that in the directory where the updates deployments are stored, is a whole lot of empty GUID.1 directories, and no updates are deployed.

if you folks have an idea, please fire em off... 

Matthew 

Software update Groups

$
0
0

When you create a new software update group for example, 2014 windows updates. You download it and it will create a Package, you distribute it.  

So next month you download a new round, lets name it, office 2014 updates. You download it create the package distribute it.

So, if o edit the membership of the office 2014 updates, and join it with 2014 windows updates,  what happen with the packages? How SCCM2012 manage this 2 separate packages and the distributions.  

Unexpected Successful SCAN on Laptops

$
0
0

We are piloting the migration of updates form WSUS into SCCM

To begin with i created a test OU and moved 2 clients into. 

The Scan went fine on them as i created GPO which overrides our default WSUS with the SUP address for this OU

I then Ran the report to see SCAN results for ALl Systems collection Expecting i will only see successful scan for these 2 clients

The Report i ran was : Scan 3 - Clients of a collection reporting a specific state secondary

However to my surprise i saw 2 additional Machines that have successfully completed the SCAN. (Both of them being Laptops)

I am not sure how that happened. 

I checked WUAHandler log on the Laptops and i see surprisingly saw that the SUP address winning over the GPO . In my opinion the our main WSUS  GPO was not applied and the laptops used Local setting the SCCM client setup after we enabled the Software Updates Client Agent .

Possibly they were using Laptop from outside.

Now that when i ran the Scan again (while they are in office) , the WUAHAndler does show the scan failed as the Main WSUS GPO applies again.

Q:What could cause this

Q:What can i do to make sure this doesnt happen.


Software updates Scan failed with error = 0xc80003f3. in SCCM 2007 client machine(win7)

$
0
0

WIN7 client machines doesn't receive software updates

when checked WUAHANDLER.log, below is the error i could see

Scan failed with error = 0xc80003f3

please suggest

SCCM Windows Updates - Client stuck on Downloading but never finishes

$
0
0
I am running SCCM 2007 with 200 clients.  I have been sucessfully performing windows updates through SCCM without an issue for about 6 months.  Recently I approved updates released in March and most of the updates installed ok, but there are two, KB938464 and KB958690, which sit on status Downloading for hours until the desktop is switched off at night.  The times reach 14 hours on some machines.

I have tried to cancel the updates by removing them from the Advertisements and from the Deployment packages but they still try to run everyday on 167 of 200 desktops.  If I manually go to Windows Update and install the updates the issue goes away, however, you can imagine my unwillingness to do this across 167 stations if I can avoid it. 

How can I do one or both of the following:

A) Cancel the updates so they no longer want to run on the clients
B) Fix the issue so the updates download properly.

The process that I use to approve and deploy updates:

Under Site Database -> Computer Management -> Software Updates
I select the updates I want to deploy and add them to a new update list.  I place a check into the box to download the files associated to the updates.
Once the update list is built I select to deploy the updates, give it a name that represents the update period
I select a template that deploys but suppresses restart in the updates.
I select a deployment package, the same one I used for all my past updates
Download from the Internet
English
Schedule
Finish.

This has worked sucessfully for months.

Thank you for any help that can be offered. 

WSUS Sync Issue between Windows 7 Clients.

$
0
0
Hi All,

We have SCCM 2007 R2 with WSUS has installed on the same server and we have windows 7 clients almost 2000 machines.

After April month patch releasing we checked wsus server "Required Cloumn for Windows 7" machines, the required count is very low "80". We checked "All Computers" field & most of Client machines status as "Not yet Reported". But servers are okey & all of the servers scanned by wsus & there is no issue. Issue with Windows 7 client. This is my issue. I updated below windows update log from one machine which is affected.

2015-04-20 08:26:56:724 492 630 PT WARNING: SyncUpdates failure, error = 0x8024400D, soap client error = 7, soap error code = 300, HTTP status code = 200 
2015-04-20 08:26:56:724 492 630 PT WARNING: SOAP Fault: 0x00012c 
2015-04-20 08:26:56:724 492 630 PT WARNING: faultstring:Fault occurred 
2015-04-20 08:26:56:724 492 630 PT WARNING: ErrorCode:InvalidParameters(7) 
2015-04-20 08:26:56:724 492 630 PT WARNING: Message:parameters.OtherCachedUpdateIDs 
2015-04-20 08:26:56:724 492 630 PT WARNING: Method:"http://www.microsoft.com/SoftwareDistribution/Server/ClientWebService/SyncUpdates" 
2015-04-20 08:26:56:724 492 630 PT WARNING: ID:a2139655-6c05-4a6d-8cf0-fd65ed75d674 
2015-04-20 08:26:56:724 492 630 PT WARNING: PTError: 0x8024400d 
2015-04-20 08:26:56:724 492 630 PT WARNING: SyncUpdates_WithRecovery failed.: 0x8024400d 
2015-04-20 08:26:56:724 492 630 PT WARNING: Sync of Updates: 0x8024400d 
2015-04-20 08:26:56:724 492 630 PT WARNING: SyncServerUpdatesInternal failed: 0x8024400d 
2015-04-20 08:26:56:724 492 630 Agent * WARNING: Failed to synchronize, error = 0x8024400D 
2015-04-20 08:26:56:724 492 630 Agent * WARNING: Exit code = 0x8024400D 
2015-04-20 08:26:56:724 492 630 Agent ********* 
2015-04-20 08:26:56:724 492 630 Agent ** END ** Agent: Finding updates [CallerId = CcmExec] 

error = 0x8024400D  - The same error code shows on scanagent.log, wuahandler.log also.
I tried below steps but not worked.

*We've not changed any Group Policys related with WSUS.
*I tried client level troubleshoot like Renamed Softwaredistripution folder, Renamed ccmroot folder & Deleted root\ccm folder also.

* Today i checked WSUS version & client's WUA version both of them showing different digits, it's on issue ?
Update Services
Microsoft Corporation
Version: 3.2.7600.226

Client version: Core: 7.6.7600.320  Aux: 7.6.7600.320

I need your assist to resolve this issue....

Thanks in Advance,

Software Update Error: 0x80004005

$
0
0

 

We seem to have several clients that can't scan or patch.  In the ScanAgent.log we see:

CScanTool::Execute- Failed at AddUpdateSource, error = 0x80004005

- - - - - -Scan Failed for ToolUniqueID={9A3A916C-C182-4801-A0B3-709F0F172D5B}, with Error=0x80004005

 

The WUAHandler.log shows:

Unable to find or read WUA Managed server policy.

Unable to read existing WUA Group Policy object. Error = 0x80004005.

Enabling WUA Managed server policy to use server: http://SERVERNAME.Company.COM:80

Failed to Add Update Source for WUAgent of type (2) and id ({9A3A916C-C182-4801-A0B3-709F0F172D5B}). Error = 0x80004005.

 

These all tend to be various clients in various OU's that have no GPO's related to WSUS.  Other clients in the same OU's are scanning and patching fine.  I have tried to uninstall and reinstall these clients, re-register WUA .dll's, upgrade the WindowsUpdateAgent, and even delete the SoftwareDistribution folder so that it would recreate it.  I still get the same errors.  I know I have had several PCs rebuilt, but that isn't the best solution if there is something else that can be done.  Any help would be greatly appreciated.

 

Thanks.

can we make one package for Multiple OS Updates

$
0
0

Hi All,

In my environment possess windows Server 2003 and 2012 (newly added 2012), recently we have added 2012 server for our environment so we suppose to push security updates from SCCM.

already we have created one package for Windows updates (for server 2003), if we added 2012 security updates also in to this package it will be impact to other OS ? or it will be deploy to complaint devices only ?

Appreciated if you  could resonances to this

Thank you

Fazal


Fazal(MCTS)

Vbscript to remotely enumerate software updates (SCCM 2007)

$
0
0

Hi

Im trying to create a VBscript to initiate enumerate software updates.

The below link has a code to do this locally.

https://msdn.microsoft.com/en-us/library/cc145902.aspx

Is it possible to get this done remotely via VBScript or even Powershell? Prefer Vbscript, as some of the servers I am targeting are Windows 2003.

What I am trying to achieve is, once we have deployed our monthly patches to the server and has been rebooted, I want to run a a script to confirm what has worked and not. The idea is for the script to remotely initiate a software scan cycle on a target machine. Then the script will remotely initiate the enumerate software updates. If the result shows that nothing is required, then its good. However, if it lists some updates are to be installed, then this machine will be flagged as non compliant.

Thanks,

DM

Internet Explorer 11 fails to install

$
0
0

hey all,

i'm trying to push IE 11 to a group of users, but the installation is failing for everyone.

i can install manually with no issues.

here's SCCM report details on software updates:

Message Details
Timestamp: 4/28/2015 4:37:59 PM Message Type: Milestone
Site Code:
Message ID: 11708
System:
Process ID: 1228
Source: SMS Client Thread ID: 3964
Component: Software Updates Installation Agent Severity: Error
Description
Update f13ddae9-edf3-4b5b-a874-14f35a089e8b application failed with returned exit code = -2147023293.
Properties
Client SMS Unique IDGUID:1B27DEA6-AA07-4EA2-B1E4-E64A0A92BC14
Sdm Type IdSite_B5CB06AE-446F-4D88-80EF-688878B0381C/SUM_f13ddae9-edf3-4b5b-a874-14f35a089e8b
Sdm Type Version1

here's WindowsUpdate.txt details:

Report    REPORT EVENT: {B7E80E45-7AB0-4FD8-9424-9698A519C565}    2015-04-28 16:37:57:757-0300    1    182    101    {F13DDAE9-EDF3-4B5B-A874-14F35A089E8B}   203    80070643    CcmExec    Failure    Content Install    Installation Failure: Windows failed to install the following update with error 0x80070643: Internet Explorer 11 for Windows 7 for x64-based Systems.

i did some searching but haven't found any solid results regarding the cause.

any help is greatly appreciated!

Viewing all 700 articles
Browse latest View live