Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

SOLVED Servers reporting 'compliant' and 'non-compliant' against SUG

Status
Not open for further replies.

PKSCCM

Member
Messages
22
Reaction score
0
Points
1
Hi,

I've built up new SCCM infrastructure and cut over the existing clients to the new SCCM. My SCCM environment is currently at build 1802.

I have a mix of Server 2008/R2, 2012 and 2016.

I have configured an IP Range, that has my site system associated with the boundary and has a boundary group assigned. This Boundary group is set to allow it to be used for site assignment. No fallback relationships have been configured.

For all OS versions, SCEP deployments work fine and populate in the ccmcache folder and install like normal. So this leads me to believe that my DP and Boundaries and Boundary Groups are configured correctly.

2008 Servers
These servers seem fine, they seem to install their patches and show up as 'Pending system restart' like normal. These are also in the same IP range as the 2012 and 2016 servers.

2012 Servers
Since I cut over to the new SCCM all but a very small percentage of the 2012 servers have been showing as 'compliant' straight away. It seems they only ever download one patch but never install it (KB890830).

For the servers that do work, they are in the same IP range boundary as the ones that don't work.
I can't find anything suspicious in clientlocation.log, locationservices.log, updatehandler.log.
I just can't seem to work out what the difference is between those that work and those that don't.

2016 Servers
These servers are showing as non-compliant and never seem to want to do anything else.

I recreated the SUG for these from scratch, and it left out the KB890830 patch and deployed it to two servers (both domain controllers). Both servers create three folders in their SCCM cache location. One server has only one folder populated with a KB file and the other server has two folders populated with Kb files. Both servers have one empty folder. Still they insist on sitting at non-compliant.

Any help would be greatly appreciated. None of it makes any sense to me.
 
You might still need to upload log files - clientlocation.log, locationservices.log, updatehandler.log. Without any clue troubleshooting such issues is difficult.
 
Unfortunately due to the nature of the client I can't upload log files. Is there anything else I can do or get for you, so you can help me trouble shoot this issue?

It seems very strange that it seems to only happen on Server 2012 and 2016.
 
I have compared the locationservices.log from a 2008 (working) and a 2012 (not working) and the 2008 has a lot more activity in it that seems relevant. Including "WSUS Path" and "created and sent location request". However the 2012 locationservices.log does not contain this information. I'm not sure why though.

I've checked the HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate location in the registry on both machines and both have the SCCM server configured in that location.
 
I tested two other 2016 servers and they seemed to work as normal. However one of the original 2016 servers still won't budge, it creates three folders in its cache folder and only downloads files in two of the three folders. Software Center shows nothing at all.

LocationServices.log shows the following at the same time I deployed the patches to it.

Current AD site of machines is Default-First-Site-Name
Created and sent location request 'a long guid'
Calling back with the following WSUS location
WSUS Path= SCCM SERVER, Version=299,LocalityEx=BoundaryGroup, SUPFallbackIn=0
Calling back with locations for WSUS request 'GUID'
Current AD site of machine is Default-First-Site-Name
Current AD site of machine is Default-First-Site-Name
Current AD site of machine is Default-First-Site-Name
Current AD site of machine is Default-First-Site-Name
Current AD site of machine is Default-First-Site-Name
Calling back with empty distribution points list
Current AD site of machine is Default-First-Site-Name
Calling back with the following distribution points
Distribution Point=SCCM Server
Calling back with locations for location request (guid)
Current AD site of machine is Default-First-Site-Name
Calling back with the following distribution points
Distribution Point=SCCM Server
Calling back with locations for location request (guid)

However it does, like I said create three folders and download two files into its cache folder.

I can see in the UpdatesDeployment.log that it is downloading the updates and shows the progress for downloading. Then it shows

EnumerateUpdates for Action (UpdateActionInstall) - Total actionable updates = 0

Why would it download patches if they aren't needed?
 
A colleague ended up working out what was going on here as I was just going around in circles.

I used saved searches to add latest patches into my SUGs. These worked fine but for reason 2012 R2 Server was not ticket in settings for WSUS to sync. So I essentially had no Server 2012 R2 patches in my SUG. So the servers had nothing to do. Some worked because I put 2012 and 2012 R2 patches in the same SUG.
 
Status
Not open for further replies.

Forum statistics

Threads
7,025
Messages
27,490
Members
17,677
Latest member
Nairolf

Trending content

Back
Top