ronnoco Posted April 19, 2021 Posted April 19, 2021 Hello all, Hoping someone can help. My colleague and I have installed SCCM from scratch. The system seems to generally be working ok. We are following MS guidance to configure Endpoint Protection as the first thing we want to do is get Defender managed on all the existing clients. We have created an automatic deployment rule to target a custom device collection called 'Win 10 Clients' We have download definition updates but how do we push these updates to our collection? Do we need to create a software update group and if so, is this a one time thing? Definitions are downloaded every day (as we have specified this) but of co-course, we don't want to be doing a manual process every day of the week. I have attached some screenshots which might help explain. Any help would very much appreciated as we are SCCM novices! Many Thanks
jtotheb Posted April 19, 2021 Posted April 19, 2021 Hello all, We have download definition updates but how do we push these updates to our collection? Do we need to create a software update group and if so, is this a one time thing? Definitions are downloaded every day (as we have specified this) In Software Library -> Software Updates -> Software Update Groups is there not a SUG that was created when you created the Auto Deployment Rule? The generation of a software update group is controlled in the properties of the Auto Deployment Rule -> General tab: Each time the rule runs and finds new updates 1) Create a new SUG 2) Add to an existing SUG. If you've created the SUG you might want to go with option 2. The "Software Updates" tab of the Auto Deployment Rule is going to determine if new definitions are added. E.g. Date Released or Revised: Last 1 day Product: System Center Endpoint Protection OR Microsoft Defender Antivirus Superseded: No Update Classification: Definition Updates The on your Evaluation Schedule tab: Either: 1)Run the rule after any software update point sync or 2) run the rule on a schedule and set the schedule accordingly. 1
ronnoco Posted April 20, 2021 Author Posted April 20, 2021 Thanks for the reply, very much appreciated. We don't have anything created in Software Update Group. These are the instructions we followed to create the automatic deployment rule. Perhaps I did something wrong here, it's been a minefield! https://docs.microsoft.com/en-us/mem/configmgr/protect/deploy-use/endpoint-definitions-configmgr How can I now create a SUG and link it to this Automatic Deployment rule? Many thanks again!
jtotheb Posted April 20, 2021 Posted April 20, 2021 Has the ADR actually run? If so, is it actually picking up any updates to deploy? If you view the properties of the Auto Deployment Rule -> Software Updates tab -> Click the "Preview" button. Is the criteria you've set picking up any updates? The SUG should be created by the rule, but if the rule isn't finding anything to deploy that might be why it isn't generating one. In the Software Update Groups section of Software Updates all of the SUGs created by ADRs have "Created By" as "AutoUpdateRuleEngine" rather than by an SCCM admin. 1
ronnoco Posted April 20, 2021 Author Posted April 20, 2021 (edited) Thanks for replying. Yes, you are correct there are no items shown in the preview. Do I need to alter the settings to 'create a new software update group?' or will this create a new group every time it runs? Perhaps I selected existing and this is why it's not working (although I would have thought it would have asked me for the name of the SUG?) Edited April 20, 2021 by ronnoco
jtotheb Posted April 23, 2021 Posted April 23, 2021 (edited) Thanks for replying. Yes, you are correct there are no items shown in the preview. Do I need to alter the settings to 'create a new software update group?' or will this create a new group every time it runs? Perhaps I selected existing and this is why it's not working (although I would have thought it would have asked me for the name of the SUG?) It should make one called "Endpoint Deployment" from the name of the rule by itself, but you haven't got any updates under the scope of the rule to deploy (empty preview window). I think that's the root cause of your problem. If the Auto Deployment Rule isn't finding anything to deploy nothing happens when the rule is run. Edit: Mine looks something like this: Edited April 23, 2021 by jtotheb
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now