Jump to content

Recommended Posts

Posted

Hi Everyone,

 

Hopefully someone can help me in the right direction as I've spent the last couple weeks smashing my head against a brick wall with SCCM. I didn't want to post anything as I was hoping I could fix the issues tracing the error codes but I think I need someone else's opinion before I melt down!

 

Been working on it for two years in my spare work time since I did a 5 day crash course on it. Finally get around to ditching our old sophos AV in order to use SCCM Endpoint, thinking, it's on most machines. I'll just trouble shoot the 1/3 that aren't currently working. Well that was three weeks ago and I'm no closer to fixing the issues I'm getting.

 

First off I can't seem to push any clients out any more as I just keep getting several lines of errors from each attempt. Below is an example. I've set several accounts up for pushing clients but have recently tried using local admin accounts to see if that can get around the issues.

 

---> Trying the 'best-shot' account which worked for previous CCRs (index = 0x0) 07/04/2017 10:40:33 7904 (0x1EE0)---> Attempting to connect to administrative share '\\infant-n16.anglesey-pri.local\admin$' using account '.\admin' 07/04/2017 10:40:33 7904 (0x1EE0)Submitted request successfully 07/04/2017 10:40:33 4236 (0x108C)Getting a new request from queue "Incoming" after 100 millisecond delay. 07/04/2017 10:40:33 4236 (0x108C)Waiting for change in directory "C:\Program Files\Microsoft Configuration Manager\inboxes\ccr.box" for queue "Incoming", (30 minute backup timeout). 07/04/2017 10:40:33 4236 (0x108C)---> WNetAddConnection2 failed (LOGON32_LOGON_NEW_CREDENTIALS) using account .\admin (00000035) 07/04/2017 10:40:33 7904 (0x1EE0)---> The device infant-n16.anglesey-pri.local does not exist on the network. Giving up 07/04/2017 10:40:33 7904 (0x1EE0)---> Trying the 'best-shot' account which worked for previous CCRs (index = 0x0) 07/04/2017 10:40:33 7904 (0x1EE0)---> Attempting to connect to administrative share '\\JUNIOR-L6\admin$' using account '.\admin' 07/04/2017 10:40:33 7904 (0x1EE0)---> WNetAddConnection2 failed (LOGON32_LOGON_NEW_CREDENTIALS) using account .\admin (0000052e) 07/04/2017 10:40:33 7904 (0x1EE0)---> The 'best-shot' account has now succeeded 0 times and failed 1 times. 07/04/2017 10:40:33 7904 (0x1EE0)---> Trying each entry in the SMS Client Remote Installation account list 07/04/2017 10:40:33 7904 (0x1EE0)---> Attempting to connect to administrative share '\\JUNIOR-L6\admin$' using account '.\admin' 07/04/2017 10:40:33 7904 (0x1EE0)---> WNetAddConnection2 failed (LOGON32_LOGON_NEW_CREDENTIALS) using account .\admin (0000052e) 07/04/2017 10:40:33 7904 (0x1EE0)---> Attempting to connect to administrative share '\\JUNIOR-L6\admin$' using account 'ANGLESEY-PRI\Administrator' 07/04/2017 10:40:33 7904 (0x1EE0)---> Connected to administrative share on machine JUNIOR-L6 using account 'ANGLESEY-PRI\Administrator' 07/04/2017 10:40:33 7904 (0x1EE0)---> Attempting to make IPC connection to share <\\JUNIOR-L6\IPC$> 07/04/2017 10:40:34 7904 (0x1EE0)---> Searching for SMSClientInstall.* under '\\JUNIOR-L6\admin$\' 07/04/2017 10:40:34 7904 (0x1EE0)---> System OS version string "6.1.7601" converted to 6.10 07/04/2017 10:40:34 7904 (0x1EE0)---> Unable to connect to WMI (root\ccm) on remote machine "JUNIOR-L6", error = 0x8004100e. 07/04/2017 10:40:34 7904 (0x1EE0)---> Creating \ VerifyingCopying existence of destination directory \\JUNIOR-L6\admin$\ccmsetup. 07/04/2017 10:40:34 7904 (0x1EE0)---> Copying client files to \\JUNIOR-L6\admin$\ccmsetup. 07/04/2017 10:40:34 7904 (0x1EE0)---> Copying file "C:\Program Files\Microsoft Configuration Manager\bin\I386\MobileClient.tcf" to "MobileClient.tcf" 07/04/2017 10:40:34 7904 (0x1EE0)---> Copying file "C:\Program Files\Microsoft Configuration Manager\bin\I386\ccmsetup.exe" to "ccmsetup.exe" 07/04/2017 10:40:35 7904 (0x1EE0)---> Updated service "ccmsetup" on machine "JUNIOR-L6". 07/04/2017 10:40:51 7904 (0x1EE0)---> Started service "ccmsetup" on machine "JUNIOR-L6". 07/04/2017 10:40:51 7904 (0x1EE0)---> Deleting SMS Client Install Lock File '\\JUNIOR-L6\admin$\SMSClientInstall.ANG' 07/04/2017 10:40:51 7904 (0x1EE0)Execute query exec [sp_CP_SetLastErrorCode] 16777285, 0 07/04/2017 10:40:51 7904 (0x1EE0)---> Completed request "16777285", machine name "JUNIOR-L6". 07/04/2017 10:40:51 7904 (0x1EE0)Deleted request "16777285", machine name "JUNIOR-L6" 07/04/2017 10:40:51 7904 (0x1EE0)Execute query exec [sp_CP_SetPushRequestMachineStatus] 16777285, 4 07/04/2017 10:40:51 7904 (0x1EE0)Execute query exec [sp_CP_SetLatest] 16777285, N'04/07/2017 09:40:51', 67 07/04/2017 10:40:51 7904 (0x1EE0)<======End request: "16777285", machine name: "JUNIOR-L6". 07/04/2017 10:40:51 7904 (0x1EE0)

 

If that wasn't bad enough, since investigating the above issues I can across some errors on the SCCM server to do with pushing out SCCM server roles.

 

On 07/04/2017 10:29:35, component SMS_MP_CONTROL_MANAGER on computer ANGLESEY-SCCM.ANGLESEY-PRI.LOCAL reported: MP Control Manager detected management point is not responding to HTTP requests. The HTTP status code and text is 500, Internal Server Error.Possible cause: Management point encountered an error when connecting to SQL Server. Solution: Verify that the SQL Server is properly configured to allow Management Point access. Verify that management point computer account or the Management Point Database Connection Account is a member of Management Point Role (msdbrole_MP) in the SQL Server database.Possible cause: The SQL Server Service Principal Names (SPNs) are not registered correctly in Active DirectorySolution: Ensure SQL Server SPNs are correctly registered. Review Q829868.Possible cause: Internet Information Services (IIS) isn't configured to listen on the ports over which the site is configured to communicate. Solution: Verify that the designated Web Site is configured to use the same ports which the site is configured to use.Possible cause: The designated Web Site is disabled in IIS. Solution: Verify that the designated Web Site is enabled, and functioning properly.Possible cause: The MP ISAPI Application Identity does not have the requisite logon privileges. Solution: Verify that the account that the MP ISAPI is configured to run under has not been denied batch logon rights through group policy.For more information, refer to Microsoft Knowledge Base article 838891.

 

DCOM was unable to communicate with the computer ANGLESEY-FTP.anglesey-pri.local using any of the configured protocols; requested by PID 28e0 (C:\Program Files\Microsoft Configuration Manager\bin\x64\smsexec.exe).

 

On 04/07/17 10:11:00, component SMS_SITE_COMPONENT_MANAGER on computer ANGLESEY-SCCM.ANGLESEY-PRI.LOCAL reported: Site Component Manager failed to install this component on this site system.Solution: Review the previous status messages to determine the exact reason for the failure. Site Component Manager will automatically retry the installation in minutes. To force Site Component Manager to immediately retry the installation, stop and restart Site Component Manager using the Configuration Manager Service Manager.

 

On 07/04/2017 10:11:00, component SMS_DISTRIBUTION_MANAGER on computer ANGLESEY-SCCM.ANGLESEY-PRI.LOCAL reported: Failed to create virtual directory on the defined share or volume on distribution point "["Display=\\ANGLESEY-FTP.anglesey-pri.local"]MSWNET:["SMS_SITE=ANG"]\\ANGLESEY-FTP.anglesey-pri.local".Possible cause: Distribution Manager requires that IIS base components be installed on the local Configuration Manager Site Server in order to create the virtual directory. Distribution Manager also requires that IIS Web Services be installed on the Distribution Point Server that needs to support Background Intelligent Transfer Service (BITS).Solution: Verify that IIS base components are installed on the local Configuration Manager Site Server, and IIS Web Services are installed on the Distribution Point Server.

 

I've checked out most, if not all of the above recommendations hoping to find something wrong but everything I've checked has been fine so far. Either I'm missing something or there's an issue not mentioned above that's having a knock on effect to the whole of SCCM. Clients can't be pushed out at the moment, even manual installs don't seem to work. Endpoint is still being updated by the looks of things so most machines are covered by the old and new AV's while I try and sort this issue out.

 

Set up includes SCCM on a 2012R2 VM, SQL on a separate 2012R2 VM and FTP physical server for software deployment. Also trying to push out and manage two separate domains.

 

I'll admit I'm a complete noob with SCCM even with 2 years of messing around with it, it's just so huge it's hard to know exactly what the issue is and I seem to follow one error only to discover a rabbit hole of problems branching out. If I can't sort SCCM out then I'm seriously considering scrapping it and setting it all up from scratch again.

 

Any help is much appreciated!

 

Kind Regards,

Alex

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...