Jump to content

Recommended Posts

Posted

Hello,

 

Apologies if this is a repeat thread, but I haven't been able to find the correct info I'm looking for here or anywhere else on the web. Have been using SCCM for quite some time, but only recently started using the SUP portion of it. I have created a Software Update Group with 119 updates contained in it (Essentially all Windows 10 Updates) as a base line to push out to my machines to make sure that they are as up to date as possible. However, the only thing that appears in the Software Center is the Windows Malicious Software Removal Tool. I have a few Windows 7 machines still in my network (I know I know...) and when I created the baseline SUG for that, it picked up all the updates and went exactly as expected. Seems to be specific to Windows 10 and, from what I can gather on the web, is likely related to Dual Scan. However, I have disabled DualScan via GPO, but just can't quite get it to work and am pretty confused as lots of sites seem to say different things from the setup. A few things to note...

 

- I have "Do not allow update deferral policies to cause scans against Windows Update" enabled via GPO

 

- I have "Specify intranet Microsoft update service location" enabled via GPO with the needed URL/Port settings

 

- My UpdatesStore.log file shows as querying against 119 updates...but then only installs the Microsoft Tool mentioned above.

 

- If I run a compliance report from SCCM, it shows the machines as being up to date. My theory on that though is that since they are only applying the Microsoft Tool and that is what is showing as needing to install, it "thinks" that it is compliant.

 

- Have confirmed that updates are not installing as, if I click the "Check online for updates from Microsoft Update", it finds the needed updates.

 

 

 

I'm sure I'm probably missing something obvious, but am about at my wits end trying to figure this out as was really proud of myself when saw my compliance numbers raise substantially when first deployed everything...then I started to notice that they weren't actually installing all of the updates.

Posted
We don't have any settings for our SCCM updates configured via GPO. As far as I know this isn't supported, all settings are managed by the SCCM agent on the individual PCs
Posted
I have had the same problem. In the end I dumped the Software Update Packages & Groups. Left it a while and then created them and it all kicked back into life.
  • Thanks 1
Posted

Thanks for the replies! Sorry for late response as had another issue that popped up that pulled me away from this for last day or so...

 

So a couple updates / notes:

 

- I went ahead and tried removing all GPO settings I had related to updates, did a GPUPdate /force on my test VM and re-ran both Software Updates Deployment Evaluation Cycle and Software Updates Scan Cycle...no luck

- In addition to the Windows Malicious Software Removal Tool being installed correctly, I have also noticed that Windows Defender updates are installing normally even though I'm not actually pushing out those via SCCM, so I assume those are coming directly from Microsoft

- I reimaged my test VM just to make sure it wasn't something in my VM as well as checked a few student desktops in one of our labs...still no updates deploying.

- I did notice as well in UpdatesDeployment.log the following error: EnumerateUpdates for action (UpdateActionInstall) - Total actionable updates = 0

- From the way I read that, it is seeing the updates in SCCM, but is thinking, for some reason, that they aren't actually "actionable", meaning needing to be installed

- Have noticed that when I got into my Search Criteria for All Software Updates, if I choose the "required" (set greater than or equal to 1), most of my updates show less than 20 machines requiring the update, but the MS Malicious tool being required by over 2000 machines (about the size of my network).

Really is an odd issue and has to be something that I'm missing on this one...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...