Security and Compliance
25 TopicsImplementing Windows 11 - updates not showing through configmgr
New admin here - our old admin left unexpectedly and I hopped in his place, so i apologize for the questions i'm about to ask as they might be simple. I originally asked on Reddit and they suggested I look here. I'm in the middle of piloting windows 11 with myself only (getting the basic TS working, DISM removing software, etc). I was waiting until this update cycle before i handed it out to a few IT folks to test their apps with, but this is when i discovered software updates were not showing as required nor installed on any of the 4 devices I installed this on. Device list 3 VMWare VM's 1 Dell 7080 ConfigMgr Version 2211 we've been using config manager here since the very early SMS days currently have about 1400 windows 10 clients fully functional VLSC Windows 11 22H2 22621.2134 Went through the guide on Prajwal Desai (https://www.prajwaldesai.com/deploy-windows-11-using-sccm-configmgr/) Imaging went off mainly without a hitch I've been pushing apps automatic mandatory apps have been installing we use patch my PC which is updating W11 clients as well without any issues. The software Update problem. No windows 11 clients are showing any required, nor installed updates on either the VM's OR the Dell desktop.   WUAHandler is showing that it has successfully scanned the device (it's identical to the W10 boxes) Summary is showing every 6 hours client settings show updates every 4 hours the image i've been using is 22621.2134 the cumulative update should be catching this https://support.microsoft.com/en-us/topic/november-14-2023-kb5032190-os-builds-22621-2715-and-22631-2715-f9e3e13c-5e98-42c2-add8-f075841ca812 if not the superseded update should be catching these at least. https://support.microsoft.com/en-us/topic/august-8-2023-kb5029263-os-build-22621-2134-f8d4d3de-47c1-40e1-a2e6-97c2770ee2e8 Like i mentioned above, applications are installing, patch my PC is installing software, so SCCM is functional to these devices, it's just not scanning W11 devices correctly (W10 is working just fine) unsure where to start looking... thanks all!Solved8.8KViews0likes8CommentsUnexpected ConfigurationType" error when attempting to onboard to Defender ATP with MECM
Crossposting from the Security and Compliance forum... I'm attempting to onboard some clients to Defender ATP using Microsoft Endpoint Configuration Manager. I've followed the instructions here:https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/configure... However, the clients are not being onboarded, and when I look at the C:\Windows\CCM\Logs\ATPHandler.log file, I see the following: ATPHandler: Handling policy originating from AdminConsole: AdvancedThreatProtectionSettings_Configuration 2020-10-21 5:09:35 PM 10148 (0x27A4) ATPHandler: Unexpected ConfigurationType, 2020-10-21 5:09:35 PM 10148 (0x27A4) ATPHandler: Failure in CATPHandler::HandleUIPolicy: 0x80070057 2020-10-21 5:09:35 PM 10148 (0x27A4) I haven't found any reference to this "ATPHandler: Unexpected ConfigurationType" error anywhere. Does anyone know what I should be looking at to troubleshoot this? MECM Client version 5.00.9012.1034, site version 5.0.9012.1000Solved3.9KViews0likes4CommentsHow to allow powershell in managed device?
HI everyone, newbie admin here. I am in the process of learning out to use the EndPoint Manager and I have enrolled my first device, which will be my work laptop. It is running windows 11 enterprise and it is enrolled in tenant with an account licensed at an 0365 A3 level. Up until there, everything seems fine, but I stumbled into a problem. I can't run powershell cmdlets. It's a fine restriction to have on 99% of the systems I'll be administering, but I need to run it on mine for user creation, and general maintence, etc. I can run the powershell cmdlets if a login as another, unmanaged , user, so it's not an install problem.  I have alllowed, through MMC the running of scripts, and through the endpoint managers the running of powershell scripts, but nothing happened. I know other policies are being applied and synced to the device, so I out of ideas. See the pictures below: Any suggestions?2KViews0likes6CommentsMECM Windows 11 Readiness Dashboard - Refresh and Queries
MECM2093introduced aWindows 11 Readiness Dashboardthat is based on data from the MECM agent/client hardware inventory. Is there a way to: See the underlying queries that are used to build this? Trigger a fresh of this Dashboard?1.9KViews0likes3CommentsCo-managed devices are being tagged as not compliant in Entra ID
Good day! Anyone experienced or familiar with this issue? 🙂 We have the following settings: 1. Conditional Access Policy that blocks Non-Compliant Devices in accessing Corporate Applications. 2. All Corporate Devices are Hybrid Azure AD Joined Devices and Co-Managed with SCCM and Intune 3. Compliance Workload of all devices are being managed by SCCM Our issue is that devices are failing Conditional Access Policy because they are tagged Not Compliant in Entra ID. When I looked in to Intune the device has the correct compliance which is "See ConfigMgr" and the Software Center of the app also shows the device is Compliant.1.9KViews0likes3CommentsSCCM CB - Windows 10 Upgrade from Windows 7 Operating System
Dear Experts, Thank You all for being great support to me!! Currently, I am running SCCM 2012 SP2 in my Environment (With Windows 7 OS) and Very soon we are on boarding SCCM CB V1710 for Windows 10 Operating System Management We are Planning to have Windows 10 OS with Version 1709 To get Started, I have followed the Upgrade readiness article, and install the required KB's and Configured the OMS (Azure) At Present, Waiting to get the response for the submitted data with OMS The End Points are running with Windows 7 and Machine is running without any interruptions. Any idea how much of time would take to see the DATA in OMS Console. At present this is done 80 Hours ago (during the time of post). The Script completed successfully, and do not find any error/warnings Please suggest, if any required actions on this. Any advice from you all is very helpful pls.1.6KViews0likes1CommentMultiple deployment types install using dependencies
Hi All, Sorry to bother you but I can't seem to find any reference to this out side of a colleague that says that we can deploy software through multiple deployment types in once instance. I have been working to develop applications for software like Python, R etc. And our members of staff constantly want new Plugins/Packages adding in so we figured that just adding an extra deployment type and a dependency to last type would suffice & be more reliable instead of updating the script but it isn't working. It says that the software is compliant even though it hasn't installed everything from the other deployment types. It seems to just be doing deployment type 1 and skipping the rest even though they are all marked as dependant on this so it shouldn't go through as far as I know. Does anyone have any ideas on this? Many Thanks, Ben1.5KViews0likes4CommentsSCCM Clients installed on Virtual Desktops duplicated in Defender Portal
Hello, We have Citrix Virtual Desktops with the Config Manager Client installed that are Azure joined. In the Microsoft 365 Defender Portal the devices keep duplicating themselves. There are non-persistent machines and I suspect that whenever they are updated from the master image that is it causing this to occur. In the Configuration Manager Server console these machines are not duplicated and only appear once. Looking for suggestions or recommendations on how to go about preventing this from occurring. Thank you, Steve1.2KViews0likes4Comments