Manny-Tech Posted May 23, 2018 Posted May 23, 2018 Bit of a peculiar one this, I'm hoping someone has come across it before. SCCM 1802 with Windows Defender (Windows 10) and Endpoint Protection 2010 (Win7 clients) I have configured my policies for clients and the antimalware policies which are taking effect, however, my Endpoint clients will not update from my SUP. They will update directly from Microsoft though. I have an ADR in place, it is pulling all the definitions through but the required field is saying 0 when if I look at a client I know it isn't up-to-date. If I run a manual update on the client it attempts to search and then comes back with no updates. Looking at the logs it is pointing to the SUP for updates, it is reporting for Win7/Win10 updates just not the definitions for SCEP. The UpdateDeployments.log shows that the updates are 'missing' which would indicate it is checking in to see what updates are required it just isn't applying them. I'm hoping someone can give me some pointers, I'm pulling my hair out with this one. I'm borderline just allowing my definitions to be pulled direct from Microsoft and stick with all other updates from the SUP.
free780 Posted May 24, 2018 Posted May 24, 2018 Make sure the update source GPO/SCCM config is set correctly. Set a test PC that won't go out to Microsoft for updates. Have you set the client settings?
sparkeh Posted May 24, 2018 Posted May 24, 2018 What update sources do you have set in client settings?
Manny-Tech Posted May 24, 2018 Author Posted May 24, 2018 My Windows Update GPO does point to my SCCM server. @sparkeh I have checked my client settings I cannot find update sources within that other than when it applies first definitions. If I look at my Malware Policies it does have update sources and it is currently set to 'Updates distributed from CM' .
sparkeh Posted May 24, 2018 Posted May 24, 2018 And to make sure, the software update group that contains the definition updates is targeted at the collection containing the clients?
Manny-Tech Posted May 24, 2018 Author Posted May 24, 2018 It is indeed. Like I said in my original post, the log file demonstrates it connecting to the SUP server and seeing the updates as missing but it just doesn't seem to apply them. I'm happy to upload any logs if needs be.
Arthur Posted May 24, 2018 Posted May 24, 2018 (edited) I have an ADR in place What do you have in your ADR search criteria? For comparison, this is mine... IIRC, there was an update that required the 'Critical Updates' classification to be added before the clients would install any definition updates. Edited May 24, 2018 by Arthur
Manny-Tech Posted May 24, 2018 Author Posted May 24, 2018 @Arthur Mine is the same product and classifications as yours I just don't have the date released or revised option.
sparkeh Posted May 24, 2018 Posted May 24, 2018 Can you post your UpdatesHandler, UpdatesDeployment and WUAHandler logs?
Manny-Tech Posted May 24, 2018 Author Posted May 24, 2018 See attached. Thanks for your guidance so far, it is much appreciated.WUAHandler.txtUpdatesDeployment.txtUpdatesHandler.txt
CHSGM Posted May 24, 2018 Posted May 24, 2018 I have a very similar problem as well. I created a similar ADR to deploy the latest 1804 definition update and although being deployed to 'All Systems' it only reached a portion of Windows 8 clients. No Win 10 clients in the network picked it up whatsoever. Still trying out as to why...
Manny-Tech Posted May 25, 2018 Author Posted May 25, 2018 @sparkeh did you get chance to take a look at the logs? I'm at a real loss with it now.
sparkeh Posted June 7, 2018 Posted June 7, 2018 @Manny-Tech sorry, I missed this :S Yes I've taken a look at the logs. The UpdatesDeployment log shows that the machine is identifying that it needs the AV updates and downloading them but when it comes to installing it, it says No current service window available to run updates assignment with time required = 1 UpdatesDeploymentAgent So it thinks that it can't install the updates. Do you use maintenance windows at all? 1
free780 Posted June 7, 2018 Posted June 7, 2018 Have you checked c:\windows\temp\mprun.log you can see if it's checking against SCCM.
CHSGM Posted June 7, 2018 Posted June 7, 2018 Ended up finding up the issue with mine - my software update point classification tree did not have the Windows Defender product enabled. Once that was on, all my clients began to pull them down. Possibly worth checking?
Manny-Tech Posted June 11, 2018 Author Posted June 11, 2018 @Manny-Tech sorry, I missed this :S Yes I've taken a look at the logs. The UpdatesDeployment log shows that the machine is identifying that it needs the AV updates and downloading them but when it comes to installing it, it says No current service window available to run updates assignment with time required = 1 UpdatesDeploymentAgent So it thinks that it can't install the updates. Do you use maintenance windows at all? I should have updated this by now. It was exactly this, I think I was getting maintenance windows and deployment times muddled up to the point where it wasn't able to run during the maintenance window. I have scrapped those now and just supress restarts for servers. Thanks for your help on this though, It's certainly pointed me in the right direction of which log files to check. SCCM is a complicated beast to begin with! 1
sparkeh Posted June 11, 2018 Posted June 11, 2018 I should have updated this by now. It was exactly this, I think I was getting maintenance windows and deployment times muddled up to the point where it wasn't able to run during the maintenance window. I have scrapped those now and just supress restarts for servers. Thanks for your help on this though, It's certainly pointed me in the right direction of which log files to check. SCCM is a complicated beast to begin with! Glad its sorted Yes, it is a beast. Getting used to the logfiles helps a lot.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now