Jump to content

Recommended Posts

Posted

Not sure where to post this as covers Cloud and On Premise

 

Recently I noticed that all hybrid joined SCCM clients were no longer being managed by SCCM and instead being managed as Intune devices via endpoint manager.

 

This in turn has had a massive knock on effect when they are powered on - more noticable in the last month as they connect to Endpoint to check in and Smoothwall grinds to a halt for a short period as it tries to deal with over 25,000-60,000 access over 15 mins.

 

After contacting ISP and Smoothwall, finally worked out it could be due to Windows updates - or a MS Service using IP 23.219.197.246

 

I jump on Endpoint Manager and realised I had some Intune settings set to all devices, I've changed these to just Azure Groups containing Intuned Laptops and then reinstalled the SCCM client on the on prem devices.

 

Endpoint manager see these as Co-Managed and to see See ConfigMgr - so all good there.

 

After a few hours of changing things when I reboot all the computers, the internet still grinds to a halt as Smoothwall tries to deal with the influx of connections.

 

Slowly pulling my hair out! Not to mention the grief I am getting from staff and the head!

 

Anyone with SCCM and Hybrid Joined devices and Intune - come across anything like this?

 

I'm at the point where I am going to start approaching companies to see if they can have a look at my setup and see what is going on and point out the error of my ways!

 

Anyone recommend companies that deal with SCCM and Intune?

 

Cheers in advance

Posted

Without knowing what you have configured on SCCM/InTune, are you mentioned Updates do you have things like Delivery Optimization configured up? Even if they're looking at SCCM for updates they can do dual updates from online at the same time, and normally reboot is when it'll first do its windows updates/edge updates checks etc.

 

Would be a nice easy test to put something like an hour delay for Windows updates via WuFB (Delivery Optimization wise) before it falls back to the internet rather than peers, and see if all the connections stop at reboot then hit an hour later

 

Do you have the SCCM client settings to automatically join to MDM enabled? Even while hybrid joined (assuming this is via AD Connect?) they shouldn't register into InTune without the additional config setup, unless that was that you actually wanted ofc

 

Did you update SCCM recently? If you've enabled Cloud Attach it recently changed the default workloads in SCCM in an update

 

Steve

Posted

We have the same hybrid management set up and don’t experience the behaviour you’re seeing.

 

The Intune Management Extension on the clients checking in with Intune shouldn’t grind your internet to a halt. What level of traffic are you seeing on your smoothwall when things go south?

 

How are the different workloads set in SCCM? Which ones have been passed over to Intune?

 

How many hybrid clients do you have?

 

Are you deploying apps from Intune to hybrid clients? If so are any failing?

 

Are you using WuFB for updates? Any issues there?

 

Are your certificates on the SCCM/Intune connection valid?

Posted

Also… and I hate to say it, the policies that you realised were incorrectly targeting “All Devices” - what were the settings doing?

 

Not all Intune policy settings get removed from client devices when policies are removed. Same as GPOs. Either a policy to undo settings is required or machines need to be rebuilt.

Posted
We have the same hybrid management set up and don’t experience the behaviour you’re seeing.

 

The Intune Management Extension on the clients checking in with Intune shouldn’t grind your internet to a halt. What level of traffic are you seeing on your smoothwall when things go south?

 

How are the different workloads set in SCCM? Which ones have been passed over to Intune?

 

How many hybrid clients do you have?

 

Are you deploying apps from Intune to hybrid clients? If so are any failing?

 

Are you using WuFB for updates? Any issues there?

 

Are your certificates on the SCCM/Intune connection valid?

 

I can’t see tell if devices are checking in or trying to do something else, all I see on smoothwall is that IP address hitting smoothwall and being dropped/rejected.

 

Approx 450 devices are hybrid join and the policies were a combination of some packages being deployed and updates.

 

I would say so as windows starts the fun begins.

 

We have power saving enabled so if any computers not being used are shutdown after 15 mins.

 

This explains why we were seeing this happening at the same times during the week.

 

I’ve paused the updates via endpoint manager and set the packages to untuned devices.

 

Packages are already deployed via SCCM image deployment, so no errors showing in deployments.

 

All devices were coming back as compliant.

 

Very last resort will be stop them being co-managed and reimagine them during Easter break.

Posted

Consider adjusting power management so your devices are able to power up and run their maintenance tasks (including Updates) overnight.

 

You should check your GPOs, Collection Settings and Intune policies and then choose one point of truth (de-configuring the others taking into account @gybe78's advice).

 

When I say one point of truth... I mean one point of truth for Pure AD/SCCM and Hybrid AAD Joined/Co-Managed, and (potentially but not necessarily) another for Pure AAD/Intune devices.

 

 

If your firewall is collapsing under the load, and it is not saturating your uplink to your ISP then I would definitely look to resolving that limitation - it could be a config tweak there and all these problems go away... or it could be you need to build a case to get a bigger firewall to support the cloud-based future.

Posted (edited)

Got to the point where I am thinking I have no idea what I am doing.

 

Did have a day off with the wife and spent most of it going over in my head what i have configured and what could be causing it.

 

Might try and spend some time on it tonight and go over things again.

 

 

On a side not - what would happen if I delete the stations from intune/azure? Would the Domain side carry on as normal?

Edited by mdrabble
Posted

Well after hours of digging around - it isn't me or any of the settings I have in place, was beginning to doubt my own sanity!

 

It looks like may be down to Cloud Connect - on boot, the agent logfiles show that it validates its config and sync a profile on boot.

 

Going to contact them and double check it is that - but fingers crossed

Posted

Well isn't Cloud Connect as they got back to me and confirmed their IP addresses used.

 

That IP does resolve back to a23-219-197-246.deploy.static.akamaitechnologies.com which is a MS server.

 

All updates stopped, removed all desktops from Intune, so now only managed via SCCM on prem.

 

Since I have now arrowed things down, I've got smoothwall support involved as I've tried to put a rule in to allow it and that is being ignored.

 

Hopefully, the more clever people than me can help resolve this.

Posted

Ticket been passed to 2nd line, and I've done some more investigating.

 

I've turned on the additional auditing and instantly I can see devices (Domain Joined devices) on my network talking to this IP but not getting the reply.

 

What is even more confusing is that a PC that was flagged was sat at the logon screen.

 

It is all upto date with updates, edge, onedrive client etc - so I have no idea what is going on!

 

Anyone else seeing traffic from 23.219.197.246 on their firewalls?

 

Cheers

Posted (edited)
Ticket been passed to 2nd line, and I've done some more investigating.

 

I've turned on the additional auditing and instantly I can see devices (Domain Joined devices) on my network talking to this IP but not getting the reply.

 

What is even more confusing is that a PC that was flagged was sat at the logon screen.

 

It is all upto date with updates, edge, onedrive client etc - so I have no idea what is going on!

 

Anyone else seeing traffic from 23.219.197.246 on their firewalls?

 

Cheers

 

Yep - doesn't affect performance though....

 

 

Screenshot 2024-03-07 111107.png

 

 

....and our devices are talking out to that address.

Edited by gybe78
  • Thanks 1
Posted (edited)

Yes. Lots of Microsoft processes are accessing it: svchost.exe msedge.exe onedrive.exe wdavdaemon (on a mac) are all initiating the connection. Often the ip resolves to go.microsoft.com

 

It is very much not all the time though, on the records for a single device I could scroll back and read off the screen all the times a device here communicated with that IP over the last week.

 

Screenshot 2024-03-07 112402.jpg

Edited by psydii
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...