mullet_man Posted July 4, 2017 Posted July 4, 2017 Hi all, I've deployed out a SCEP policy to my devices but when I check the client device it seems to show both the Default Client Antimalware Policy as well as my policy I've defined. Also if I go to update definitions I get the following error The logs seem to show its checking WU online to get the updates even though I've got ConfigMgr to deploy my definitions. any ideas, not sure if this is a Windows 10 1703 thing? Does anyone else policy show two defined? When I've googled others only seem to have one? You can't deploy out the default so not sure why it should show up? Cheers.
sparkeh Posted July 4, 2017 Posted July 4, 2017 Yeah ours shows both. I'll take a better look in the morning but I thought that was normal and your own policy took precedence.
mullet_man Posted July 4, 2017 Author Posted July 4, 2017 Thanks @sparkeh I bet your right but I've seen ones from online and it seems to only show one. Unless the default one can be renamed and that's how they've got one to show? Trying to push my updates out via SCCM but finding it a bit of pain to get setup.
dblight Posted July 4, 2017 Posted July 4, 2017 Your additional policy will take over the default policy 1
mullet_man Posted July 5, 2017 Author Posted July 5, 2017 Your additional policy will take over the default policy Thanks, I just need to work out why my Endpoint brings up that -2147023728 error then now.
sparkeh Posted July 5, 2017 Posted July 5, 2017 Thanks, I just need to work out why my Endpoint brings up that -2147023728 error then now. I would start by looking at the UpdatesDeployment.log in C:\Windows\CCM\Logs\ That might give you are more meaningful error message.
mullet_man Posted July 7, 2017 Author Posted July 7, 2017 Turns out you can't use a Server 2016 WSUS for SUP on a 2012 r2 server running SCCM. This is where I've been having trouble getting updates to sync etc. I've installed WSUS on my sccm server now and all the updates are syncing now, just haven't seen clients pick up any updates as yet.
mullet_man Posted July 11, 2017 Author Posted July 11, 2017 After a few days of fighting it looks like clients are picking up the endpoint definitions. I don't like the fact that if you click update it doesn't actual check for updates on demand.
mullet_man Posted July 17, 2017 Author Posted July 17, 2017 OK. So after finally getting updates to install via SCCM am running into an error where staff laptops even though my Endpoint policy has Microsoft Update defined won't update online. Turns out you need to opt into Microsoft Update https://support.microsoft.com/en-gb/help/2832355/updating-the-anti-malware-definitions-in-fep-or-scep-fails-with-error Why do MS make everything so confusing and difficult. Is there an easy way to get the laptops to opt into to Microsoft Update?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now