mdrabble Posted March 5, 2024 Posted March 5, 2024 Not sure where to post this as covers Cloud and On Premise Recently I noticed that all hybrid joined SCCM clients were no longer being managed by SCCM and instead being managed as Intune devices via endpoint manager. This in turn has had a massive knock on effect when they are powered on - more noticable in the last month as they connect to Endpoint to check in and Smoothwall grinds to a halt for a short period as it tries to deal with over 25,000-60,000 access over 15 mins. After contacting ISP and Smoothwall, finally worked out it could be due to Windows updates - or a MS Service using IP 23.219.197.246 I jump on Endpoint Manager and realised I had some Intune settings set to all devices, I've changed these to just Azure Groups containing Intuned Laptops and then reinstalled the SCCM client on the on prem devices. Endpoint manager see these as Co-Managed and to see See ConfigMgr - so all good there. After a few hours of changing things when I reboot all the computers, the internet still grinds to a halt as Smoothwall tries to deal with the influx of connections. Slowly pulling my hair out! Not to mention the grief I am getting from staff and the head! Anyone with SCCM and Hybrid Joined devices and Intune - come across anything like this? I'm at the point where I am going to start approaching companies to see if they can have a look at my setup and see what is going on and point out the error of my ways! Anyone recommend companies that deal with SCCM and Intune? Cheers in advance
Steve21 Posted March 5, 2024 Posted March 5, 2024 Without knowing what you have configured on SCCM/InTune, are you mentioned Updates do you have things like Delivery Optimization configured up? Even if they're looking at SCCM for updates they can do dual updates from online at the same time, and normally reboot is when it'll first do its windows updates/edge updates checks etc. Would be a nice easy test to put something like an hour delay for Windows updates via WuFB (Delivery Optimization wise) before it falls back to the internet rather than peers, and see if all the connections stop at reboot then hit an hour later Do you have the SCCM client settings to automatically join to MDM enabled? Even while hybrid joined (assuming this is via AD Connect?) they shouldn't register into InTune without the additional config setup, unless that was that you actually wanted ofc Did you update SCCM recently? If you've enabled Cloud Attach it recently changed the default workloads in SCCM in an update Steve
5tu Posted March 5, 2024 Posted March 5, 2024 We have the same hybrid management set up and don’t experience the behaviour you’re seeing. The Intune Management Extension on the clients checking in with Intune shouldn’t grind your internet to a halt. What level of traffic are you seeing on your smoothwall when things go south? How are the different workloads set in SCCM? Which ones have been passed over to Intune? How many hybrid clients do you have? Are you deploying apps from Intune to hybrid clients? If so are any failing? Are you using WuFB for updates? Any issues there? Are your certificates on the SCCM/Intune connection valid?
5tu Posted March 5, 2024 Posted March 5, 2024 Also… and I hate to say it, the policies that you realised were incorrectly targeting “All Devices” - what were the settings doing? Not all Intune policy settings get removed from client devices when policies are removed. Same as GPOs. Either a policy to undo settings is required or machines need to be rebuilt.
mdrabble Posted March 5, 2024 Author Posted March 5, 2024 We have the same hybrid management set up and don’t experience the behaviour you’re seeing. The Intune Management Extension on the clients checking in with Intune shouldn’t grind your internet to a halt. What level of traffic are you seeing on your smoothwall when things go south? How are the different workloads set in SCCM? Which ones have been passed over to Intune? How many hybrid clients do you have? Are you deploying apps from Intune to hybrid clients? If so are any failing? Are you using WuFB for updates? Any issues there? Are your certificates on the SCCM/Intune connection valid? I can’t see tell if devices are checking in or trying to do something else, all I see on smoothwall is that IP address hitting smoothwall and being dropped/rejected. Approx 450 devices are hybrid join and the policies were a combination of some packages being deployed and updates. I would say so as windows starts the fun begins. We have power saving enabled so if any computers not being used are shutdown after 15 mins. This explains why we were seeing this happening at the same times during the week. I’ve paused the updates via endpoint manager and set the packages to untuned devices. Packages are already deployed via SCCM image deployment, so no errors showing in deployments. All devices were coming back as compliant. Very last resort will be stop them being co-managed and reimagine them during Easter break.
psydii Posted March 5, 2024 Posted March 5, 2024 Consider adjusting power management so your devices are able to power up and run their maintenance tasks (including Updates) overnight. You should check your GPOs, Collection Settings and Intune policies and then choose one point of truth (de-configuring the others taking into account @gybe78's advice). When I say one point of truth... I mean one point of truth for Pure AD/SCCM and Hybrid AAD Joined/Co-Managed, and (potentially but not necessarily) another for Pure AAD/Intune devices. If your firewall is collapsing under the load, and it is not saturating your uplink to your ISP then I would definitely look to resolving that limitation - it could be a config tweak there and all these problems go away... or it could be you need to build a case to get a bigger firewall to support the cloud-based future.
mdrabble Posted March 5, 2024 Author Posted March 5, 2024 (edited) Got to the point where I am thinking I have no idea what I am doing. Did have a day off with the wife and spent most of it going over in my head what i have configured and what could be causing it. Might try and spend some time on it tonight and go over things again. On a side not - what would happen if I delete the stations from intune/azure? Would the Domain side carry on as normal? Edited March 5, 2024 by mdrabble
mdrabble Posted March 5, 2024 Author Posted March 5, 2024 Well after hours of digging around - it isn't me or any of the settings I have in place, was beginning to doubt my own sanity! It looks like may be down to Cloud Connect - on boot, the agent logfiles show that it validates its config and sync a profile on boot. Going to contact them and double check it is that - but fingers crossed
mdrabble Posted March 6, 2024 Author Posted March 6, 2024 Well isn't Cloud Connect as they got back to me and confirmed their IP addresses used. That IP does resolve back to a23-219-197-246.deploy.static.akamaitechnologies.com which is a MS server. All updates stopped, removed all desktops from Intune, so now only managed via SCCM on prem. Since I have now arrowed things down, I've got smoothwall support involved as I've tried to put a rule in to allow it and that is being ignored. Hopefully, the more clever people than me can help resolve this.
mdrabble Posted March 7, 2024 Author Posted March 7, 2024 Ticket been passed to 2nd line, and I've done some more investigating. I've turned on the additional auditing and instantly I can see devices (Domain Joined devices) on my network talking to this IP but not getting the reply. What is even more confusing is that a PC that was flagged was sat at the logon screen. It is all upto date with updates, edge, onedrive client etc - so I have no idea what is going on! Anyone else seeing traffic from 23.219.197.246 on their firewalls? Cheers
5tu Posted March 7, 2024 Posted March 7, 2024 (edited) Ticket been passed to 2nd line, and I've done some more investigating. I've turned on the additional auditing and instantly I can see devices (Domain Joined devices) on my network talking to this IP but not getting the reply. What is even more confusing is that a PC that was flagged was sat at the logon screen. It is all upto date with updates, edge, onedrive client etc - so I have no idea what is going on! Anyone else seeing traffic from 23.219.197.246 on their firewalls? Cheers Yep - doesn't affect performance though.... ....and our devices are talking out to that address. Edited March 7, 2024 by gybe78 1
psydii Posted March 7, 2024 Posted March 7, 2024 (edited) Yes. Lots of Microsoft processes are accessing it: svchost.exe msedge.exe onedrive.exe wdavdaemon (on a mac) are all initiating the connection. Often the ip resolves to go.microsoft.com It is very much not all the time though, on the records for a single device I could scroll back and read off the screen all the times a device here communicated with that IP over the last week. Edited March 7, 2024 by psydii 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now