Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

PENDING Retrieval of Policies very very slow

clivebuckwheat

New Member
Messages
4
Reaction score
0
Points
1
Hi
I upgraded my ConfigMgr Site Server to 2309, all pre-requisites were in place before hand. Now when I pxe boot or use boot media if I open up the smsts.log I get the following" in SSL but no client cert" This will roughly loop for about 5-10 minutes and then the Advertisting task sequence window will show up, if you pick a task sequence it will take forever again on resolving dependencies and then the OSD happens"

Sometimes it's blazing fast which is rare, most of the time it's slow as hell. All models of computers this is happening on. I have updated the boot image we use to deploy are task sequences on the distribution point. Any advice from anyone would greatly be appreciated as I am ripping out my hair.
 
are you only using up ranges for boundaries? What do the logs say is taking all the time?
 
We use Active directory as the boundaries, not IP's, it loops on in SSL but no client cert for about 10 minutes before the advertise task sequence window pops up.

1. I have removed the management point and re-installed it
2. I have created a new Boot image and distributed it to the distribution point
3. I have put a machine on the same vlan as the site server to rule out any network routers and the problem is still existent.
The site server is in HTTPS/PKI but when I image a station after waiting 10 plus minutes for the retrieval of policy if you look in Configuration Manager in control panel the client certificate says self-signed not PKI which I know is incorrect.

Honestly I am super stumped.
 
Last edited:
I can recommend two things: use IP ranges for boundaries and involve the network team. They can tell you why there is a delay in devices getting the TS advertisements.
 
I can recommend two things: use IP ranges for boundaries and involve the network team. They can tell you why there is a delay in devices getting the TS advertisements.
I have a ticket with Microsoft and worked with them for about 4 hours. The task sequences are advertised to all unknown computers, the pc's we are trying to image are not in SCCM, but when we delete a pc SCCM is assigning a guid to the unknown pc and you can see in the SMSTS.log it's downloading 177 policies. The problem is unresolved as of yet.
 
I have a ticket with Microsoft and worked with them for about 4 hours. The task sequences are advertised to all unknown computers, the pc's we are trying to image are not in SCCM, but when we delete a pc SCCM is assigning a guid to the unknown pc and you can see in the SMSTS.log it's downloading 177 policies. The problem is unresolved as of yet.
Let us know how it goes. I believe MS support will look into the logs and resolve this issue.
 

Forum statistics

Threads
7,136
Messages
27,873
Members
18,159
Latest member
jordysmits
Back
Top