Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

PENDING Endpoint Protection definitions fail to download and install SCCM 2111

  • Thread starter Thread starter Miti88
  • Start date Start date
  • Replies Replies 2
  • Views Views 3K

Miti88

New Member
Messages
4
Reaction score
0
Points
1
Hi,

Wondering if I can get some advice on the below please..

We have a site running 2111 (latest hotfix applied) that has been failing to download and install definitions to NEW client devices since upgrading to 2111, oddly pre-existing devices prior to upgrading to 2111 with the SCEP client on them are fine and can download definition updates from the package no problem, devices are on 20H2 and we have plenty of devices that existed prior to upgrading to 2111 that are still updating fine.

New build devices are stuck on the latest definitions of 24/09/2019 and the Endpoint Engine version remains on 1.1.1.16400.2:
1643889145448.png

We can manually download and install definitions and engine updates from Microsoft Update externally and install them but the client still isn't able to pull the updates down from SCCM after this so I don't think it's as simple as applying an earlier update unfortunately. We have alternate sources set to use Windows Update externally if it can't pull them from the source package but nothing gets cached or installed.

The client knows which updates are missing and need installing from the SUG based on the UpdatesStore.log:

1643889402472.png

Despite this though nothing is cached and nothing gets installed.

What we have tried:

Validated all site components are healthy
Recreated ADR, Definitions Package, and SUG
Reinstall MEM client and SCEP client
Manual install of definition/engine update
Validated Boundaries and Groups

The same devices that fail to download their SCEP definitions can download WSUS updates and deploy applications from Config Manager sources fine. We can also trigger quick, full scans, and apply exclusion policies to these devices fine, they appear as 'Managed' by EP so the correct policies are applying.

One difference we noticed on new devices that fail to download SCEP updates are missing content within the C:\ProgramData\Microsoft\Windows Defender\Platform

Non-working device which fails to download definitions from configuration manager:

1643889962794.png
Working device with up to date definitions from configuration manager:

1643889911646.png


Any ideas or help would be most welcome.

Thanks
 
Any ideas on this one please folks ? The issue is becoming more pressing as we build more devices in our environment, the AV Definition remain on the initial build version of 24/09/2019 and doesn't update from there. The issue happens across different platforms 1809,1903,21h1, and we can replicate the issue on a virtual device so it isn't specific to a specific make or model.

I can still push normal windows updates and applications to affected devices fine, I can also browse from an affected machine to the internal URL of the definitions update referenced in the DataTransferService.log of a machine that IS working so there doesn't appear to be anything permission or IIS related there.

The SUP is HTTPS enabled as is the management point but we have numerous pre-existing clients still downloading these definitions fine.

Thanks
 
I can see differences in the DataTransferService.log between working and non-working devices, on the working device I see references to the required definitions updates and requests to download that content with a complete notification.
DataTransferService.log (Working Device):

1653490462128.png

If I run a software update scan on a non-working device I can see a new DTSJob gets created but there is never any reference to the URLs for the required EP definitions so they seem to be evaluating this differently and I have no idea why.

DataTransferService.log (Non Working Device)
1653490181846.png
 

Forum statistics

Threads
7,163
Messages
27,957
Members
18,250
Latest member
leopacio

Trending content

Back
Top