Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

PENDING SCCM VM CRASH SINCE CYBER ATTACK HOW DEMOTE OLD TO INSTALL NEW

PASCAL JOURDAN

Well-Known Member
Messages
120
Solutions
3
Reaction score
2
Points
18
Hi Guys
We having a pb after a cyber attack on our instrastructure .
SCCM SERVER 2019 WINDOWS VM WAS CRYPTED AND DEAD . I WANT TO KNOW HOW DEMOTE OLDER AND ALL REGISTRED FILE ON ACTIVE DIRECTORY TO INSTALL NEW SERVER SCCM.
REGARDS
 
Hi Pascal, What is this "pb" in your question?. If the attacker has encrypted the ConfigMgr Server along with other VMs, i think you must first disconnect it from network as there are chances that the malware can spread to other machines.

If you are talking about files from System Management container, you can leave them as it as and setup ConfigMgr with new site code. If the older ConfigMgr setup doesn't exist at all, you can delete the files from System Management container. You don't have to extend the AD schema again.
 
Hi Prajwal,
Tks for your answer .
Cyber attack encrypted all VM but our Active Directory is ok right.
We have set a new infrastructure with old Active Directory but the old entry SCCM block us to install a new server SCCM .

ConfigMgr setup doesn't exist at all, you can delete the files from System Management container.
Can you give me more precision to deleted old entry ?
You tell me that i can do that on AD ?
from System Management container ?
Tks
Pascal
 

Attachments

  • sccm.JPG
    sccm.JPG
    87.3 KB · Views: 3

Forum statistics

Threads
7,144
Messages
27,896
Members
18,192
Latest member
ApopoBZH

Trending content

Back
Top