Jump to content

Recommended Posts

Posted

Bit of a peculiar one this, I'm hoping someone has come across it before. SCCM 1802 with Windows Defender (Windows 10) and Endpoint Protection 2010 (Win7 clients) I have configured my policies for clients and the antimalware policies which are taking effect, however, my Endpoint clients will not update from my SUP. They will update directly from Microsoft though. I have an ADR in place, it is pulling all the definitions through but the required field is saying 0 when if I look at a client I know it isn't up-to-date. If I run a manual update on the client it attempts to search and then comes back with no updates. Looking at the logs it is pointing to the SUP for updates, it is reporting for Win7/Win10 updates just not the definitions for SCEP. The UpdateDeployments.log shows that the updates are 'missing' which would indicate it is checking in to see what updates are required it just isn't applying them.

 

I'm hoping someone can give me some pointers, I'm pulling my hair out with this one. I'm borderline just allowing my definitions to be pulled direct from Microsoft and stick with all other updates from the SUP.

Posted
Make sure the update source GPO/SCCM config is set correctly. Set a test PC that won't go out to Microsoft for updates. Have you set the client settings?
Posted
My Windows Update GPO does point to my SCCM server. @sparkeh I have checked my client settings I cannot find update sources within that other than when it applies first definitions. If I look at my Malware Policies it does have update sources and it is currently set to 'Updates distributed from CM' .
Posted
It is indeed. Like I said in my original post, the log file demonstrates it connecting to the SUP server and seeing the updates as missing but it just doesn't seem to apply them. I'm happy to upload any logs if needs be.
Posted (edited)
I have an ADR in place

What do you have in your ADR search criteria? For comparison, this is mine...

 

K5HDtvX.png

 

IIRC, there was an update that required the 'Critical Updates' classification to be added before the clients would install any definition updates.

Edited by Arthur
Posted

I have a very similar problem as well. I created a similar ADR to deploy the latest 1804 definition update and although being deployed to 'All Systems' it only reached a portion of Windows 8 clients.

 

No Win 10 clients in the network picked it up whatsoever. Still trying out as to why...

  • 2 weeks later...
Posted

@Manny-Tech sorry, I missed this :S

 

Yes I've taken a look at the logs. The UpdatesDeployment log shows that the machine is identifying that it needs the AV updates and downloading them but when it comes to installing it, it says

No current service window available to run updates assignment with time required = 1	UpdatesDeploymentAgent

So it thinks that it can't install the updates.

 

Do you use maintenance windows at all?

  • Thanks 1
Posted

Ended up finding up the issue with mine - my software update point classification tree did not have the Windows Defender product enabled.

 

Once that was on, all my clients began to pull them down.

 

Possibly worth checking?

Posted
@Manny-Tech sorry, I missed this :S

 

Yes I've taken a look at the logs. The UpdatesDeployment log shows that the machine is identifying that it needs the AV updates and downloading them but when it comes to installing it, it says

No current service window available to run updates assignment with time required = 1    UpdatesDeploymentAgent

So it thinks that it can't install the updates.

 

Do you use maintenance windows at all?

 

I should have updated this by now. It was exactly this, I think I was getting maintenance windows and deployment times muddled up to the point where it wasn't able to run during the maintenance window. I have scrapped those now and just supress restarts for servers.

 

Thanks for your help on this though, It's certainly pointed me in the right direction of which log files to check.

 

SCCM is a complicated beast to begin with!

  • Thanks 1
Posted
I should have updated this by now. It was exactly this, I think I was getting maintenance windows and deployment times muddled up to the point where it wasn't able to run during the maintenance window. I have scrapped those now and just supress restarts for servers.

 

Thanks for your help on this though, It's certainly pointed me in the right direction of which log files to check.

 

SCCM is a complicated beast to begin with!

 

Glad its sorted :)

Yes, it is a beast. Getting used to the logfiles helps a lot.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...