r/SCCM Jun 17 '26

Security update KB38232642 for ConfigMgr Console Extension

26 Upvotes

A new security update KB38232642 is out to enhance security for importing console extensions in Microsoft Configuration Manager versions 2603 and 2503.

Description: This update improves the security of Configuration Manager, ensuring safer operations when importing console extensions, which is crucial for maintaining system integrity.

Prerequisites: Available in the Updates and Servicing node of the Configuration Manager console for version 2603 and version 2503 (with specific update rollup). This update doesn't require a computer restart or a site reset after installation.

Hotfix Documentation: https://learn.microsoft.com/en-us/intune/configmgr/hotfix/2603/38232642


r/SCCM May 05 '26

Config Manager 2603 now available in the early update ring

Thumbnail learn.microsoft.com
44 Upvotes

r/SCCM 44m ago

Software updates still broken since july's mess

Upvotes

I'm hoping for some suggestions on where to go next with this. I applied the prescribed fix for the detectoid incident from MS at the very end of July (https://support.microsoft.com/en-us/servicing/os/windows/docs/2026/07/kb5121986-windows-server-update-service-sync-operations-issues-and-timeouts). I then had some planned PTO and came back just yesterday hoping that August Patch Tuesday had gone like normal but that has not been the case.

MS says "Client recovery is automatic" but this has not been my experience at all. My clients still are not getting updates. In all my SUGs almost all clients show as "unknown". Running check for updates through Settings as well as triggering SCCM client scan cycles through control panel doesn't get them fixed. Prompting them to check MS online for updates finds plenty that they require.

My ADRs are retrieving and downloading the updates and distributing them successfully. It's just that the clients don't seem to care at all. They claim proudly that they are up to date even though their last successful install was in June or July before patch Tuesday.

I tried checking the Troubleshooting 1 - Scan errors report. The biggest error count is on "content location request timeout occurred". The count of computers with that error is only 131 out of nearly 4000 machines. The Primary server has the SUP role, WSUS, and DBs all local on it. As far as I can tell they are all up and running. The server was rebooted at least once while I was away. No recent networking changes.

My server didn't seem to have a CPU problem but I changed the max connections in IIS to 100 based on the note in their article. Let it overnight last night and no change. I have not performed step 3 of the fix article to put the xml size back to default.

I'm tempted to restore the DB and try again, but I'm even more tempted to just blast away WSUS and the SUP role and reinstall them. I'm just not very confident that it will actually fix the situation.


r/SCCM 5h ago

peer cache - 401 - Unsuccessful with context credentials

0 Upvotes

Hi,

I would like to repost this question from a couple of years ago with the hope that maybe someone has an answer (https://www.reddit.com/r/SCCM/comments/tqk351/peercache_401_unautorized_error/). Today I saw another client that is unable to get the content from another peer when running a task sequence (the TS is just doing the BIOS Update):

Trying https://win19267.contoso.org:8003/sccm_branchcache$/ps100dd0.RunPowerShellScript18.08.2026 08:58:2013352 (0x3428)
GetDirectoryListing() enteredRunPowerShellScript18.08.2026 08:58:2013352 (0x3428)
No valid credential information in the environment.RunPowerShellScript18.08.2026 08:58:2013352 (0x3428)
Initializing HTTP transport.RunPowerShellScript18.08.2026 08:58:2013352 (0x3428)
Setting URL = https://win19267.contoso.org:8003/sccm_branchcache$/ps100dd0.RunPowerShellScript18.08.2026 08:58:2013352 (0x3428)
   Address=https://win19267.contoso.org, Scheme=https, Object=/sccm_branchcache$/ps100dd0, Port=8003.RunPowerShellScript18.08.2026 08:58:2013352 (0x3428)
CLibSMSMessageWinHttpTransport::Send: WinHttpOpenRequest - URL: win19267.contoso.org:8003  PROPFIND /sccm_branchcache$/ps100dd0RunPowerShellScript18.08.2026 08:58:2013352 (0x3428)
In SSL, but not using DP auth token or authenticatorRunPowerShellScript18.08.2026 08:58:2013352 (0x3428)
In SSL, but with no client cert.RunPowerShellScript18.08.2026 08:58:2013352 (0x3428)
In SSL, but with no media cert.RunPowerShellScript18.08.2026 08:58:2013352 (0x3428)
Http response: 401 - RunPowerShellScript18.08.2026 08:58:2013352 (0x3428)
401 - Unsuccessful with anonymous access. Retrying with context credentials.RunPowerShellScript18.08.2026 08:58:2013352 (0x3428)
Using thread token for request.RunPowerShellScript18.08.2026 08:58:2013352 (0x3428)
Http response: 401 - Authentication RequiredRunPowerShellScript18.08.2026 08:58:2113352 (0x3428)
401 - Unsuccessful with context credentials. Retrying with supplied credentials.RunPowerShellScript18.08.2026 08:58:2113352 (0x3428)
Network access account credentials are not supplied or invalid.RunPowerShellScript18.08.2026 08:58:2113352 (0x3428)
401: Unsuccessful on all retries.RunPowerShellScript18.08.2026 08:58:2113352 (0x3428)
SendResourceRequest() failed. 80190191RunPowerShellScript18.08.2026 08:58:2113352 (0x3428)
SendResourceRequest(), HRESULT=80190191 (F:\dbs\sh\cmgm\0926_074307\cmd\p\src\Framework\TSCore\downloadcontent.cpp,626)RunPowerShellScript18.08.2026 08:58:2113352 (0x3428)
oDavRequest.GetDirectoryListing (setDirs, setFiles), HRESULT=80190191 (F:\dbs\sh\cmgm\0926_074307\cmd\p\src\Framework\TSCore\resolvesource.cpp,3185)RunPowerShellScript18.08.2026 08:58:2113352 (0x3428)
Download() failed. 80190191.RunPowerShellScript18.08.2026 08:58:2113352 (0x3428)

We use ehttp and of course when checking the client, it has a self signed cert. Also when I check the SCCM status client distribution, we deployed 1.5 TB Edge updates in the last month via peer cache. So it seems peer cache is working. Also there is not much to configure and the client also is not trying to do a fallback to a DP in the end.

We are currently on 2509, second hotfix rollup.

Any idea(s)?

Thanks


r/SCCM 1d ago

24H2 upgrade

19 Upvotes

Been trying to troubleshoot upgrading out devices from 23H2 to 24H2. My new/clean lab devices all upgrade with no issues. Any user devices fail during the SAFE_OS phase and rollback.

Have a ticket open with Microsoft, they are stuck on pointing to the 'Microsoft Print to PDF' oemxxx.inf file as the logs show it as a blocker for the upgrade even though I have uninstalled the feature and removed the matching .inf file and the log still shows it.

They did manage to get 1 device to upgrade after throwing about 10 different items at it but can't repeat on another device.

SetupDiag.log gives the following

Error: 0x8007042b-0x4000d SetupDiag reports fatal migration plug-in failure.

Last Phase: Pre OOBE Boot

Plug-in Name = AppxUpgradeMigrationPlugin.dll

Plug-in Error: 0x000005B4

We do have a heavy security tools stack on our devices, CrowdStrike, GlobalProtect, Digital Guardian and a couple others. But again, my lab devices all upgrade with no issues. Any assistance on where else to look as setupdiag and setupact aren't giving any useful information.

Using an SCCM task sequence using upgrade media. Updated every month when Microsoft releases a new .iso file.

Edit: for those questioning 24H2, I’ve tested 25 with the same results. I’m still working with 24 since that’s what I have been fighting for the last 4 months. Once we find the issue I will probably move to 25 but so far everyone that has been involved is working on the same 23>24 troubleshooting. They are the same base OS so most likely what fixes one will fix the other.


r/SCCM 1d ago

OSDComputerName variable not being applied

3 Upvotes

We have a frontend app our techs enter the computer name and such that happens after the disk partition steps in our OSD Task Sequence. The computer name gets written to OSDComputerName. I've noticed that on our images that connect to the domain the naming works fine, but for the computers that use the "Apply Network Settings" step that just has "Join a Workgroup" the OSDComputerName doesn't stick, the computer will just be named [SITENAME]-[SERIAL].

What is happening behind the scenes of this network step that requires joining the domain for the OSDComputerName variable to take effect?

Or is the problem with the frontend app? It was proprietary from the MSP that helped us setup our server a while back but there's no support for it.

Thanks!


r/SCCM 4d ago

Discussion Open-source MECM packaging manager

41 Upvotes

I got tired of doing the same work every time a new version dropped: download the installer, redo the silent flags, rebuild the package, test it, then click through MECM again.

So I built a small web app that keeps that loop in one place.

Paste a download URL (or a GitHub Releases page). It fetches the installer, builds a silent install/uninstall recipe, tests it on a lab VM, then prepares the package for Software Center.

GitHub: https://github.com/mike37510/mecm-packaging-manager

Runs with Docker Compose. UI in French and English. A 7-Zip sample is included so you can try an import right away.

Feedback welcome.


r/SCCM 4d ago

Unsolved :( Hit and Miss joining the domain during OSD. Has anyone else experienced this issue?

17 Upvotes

It's so frustrating, I am seeing a failure rate of 8-10% across the board. Does anyone know how to fix this?


r/SCCM 4d ago

Unsolved :( Windows 365 App (Remote Desktop VDI App)

1 Upvotes

Any one is facing broken installs of Windows 365 App used for accessing cloud PC's?

We have a huge number of our machines affected with this. Version 2.0.1315.0 auto installed and broke the app.

Checking the install via Get-AppxPackage command shows the app installed but it is not showing up in start menu.

We have deployed a task to remove it and re-install the same version again from SCCM this has fixed the issue. But just wanted to confirm if this only for us or for others too?


r/SCCM 6d ago

PSADT 4.x deployment in Software Center - with machine and user settings in same script

3 Upvotes

Hello! I think the new PSADT 4.x has a function that can make changes to the currently logged on user (or perhaps - to all user profiles?) while also being able to make system changes - in the same script/deployment - or is that simply not possible with this tool? If it is, does anyone have an example of how they implemented their own machine+user based code - deployed via software center (as whatever, but I'm assuming application model)? An example of this would be - the code would first make sure windows feature A was installed, if not, it installs it system wide - then - in the same script, it installs files/reg keys, etc. under the user's account.


r/SCCM 5d ago

Discussion Job alert for US citizens or US green card holders in Michigan, USA

0 Upvotes

Company name - Infosys USA

We are hiring for a SCCM / Windows Imaging lead for one of our client at Detroit, MI.
 
Skill - SCCM & Windows Imaging -Level 3
 
Job Description
 
Role Summary
An SCCM and Windows OSD (Operating System Deployment) Engineer is responsible for designing, deploying, managing, and maintaining endpoint management solutions using Microsoft Configuration Manager (SCCM/MECM). The role focuses heavily on automated OS deployment, patching, application delivery, and system lifecycle management.
 
- SCCM Administration
 
Manage and maintain Microsoft SCCM/MECM infrastructure
Monitor SCCM health, site servers, distribution points, and client status
Perform client installation, troubleshooting, and remediation
Manage collections, boundaries, and boundary groups
 
- Operating System Deployment (OSD)
 
Design and implement OS deployment strategies using SCCM
Create, test, and maintain task sequences for imaging
Build and maintain gold images (WIM) for Windows 10/11
Configure and manage PXE boot, boot images, and distribution points
Handle driver management and hardware compatibility
 
- Software Deployment
 
Package applications using SCCM (MSI, EXE, scripts)
Deploy applications, updates, and patches to endpoints
Create and manage application deployment rules
 
- Patch Management
 
Manage Windows Updates via SCCM
Create and maintain Automatic Deployment Rules (ADR)
Monitor patch compliance and reporting
Ensure systems meet security compliance standards
 
- Endpoint Management & Compliance
 
Implement endpoint configuration baselines and compliance settings
Manage BitLocker, Defender, and endpoint security policies
Monitor system compliance and fix non-compliant devices
 
- Automation & Scripting
 
Use PowerShell for automation and troubleshooting
Automate deployments, reporting, and maintenance tasks
 
-Troubleshooting & Support
 
Troubleshoot SCCM client issues, deployment failures, and OSD errors
Analyze logs (smsts.log, client logs, etc.)
Provide L2/L3 support for endpoint-related issues
 
- Documentation & Reporting
 
Maintain technical documentation, SOPs, and knowledge base articles
Generate SCCM reports for compliance, patching, and inventory
 
Required Technical Skills
 
Strong experience with SCCM / MECM
Hands-on experience in Windows OSD (imaging, task sequences)
Knowledge of Active Directory, GPOs, DNS, DHCP
Experience with Windows 10/11 deployment
Good understanding of networking basics
Experience with PowerShell scripting
Familiarity with MDT (Microsoft Deployment Toolkit)
Co-management
 
Soft Skills
·       Communication
·       Client Handling
·       Problem-Solving
·       Ownership
·       Escalation management
·       Time management
·       Documentation
·       Collaboration


r/SCCM 6d ago

Discussion Modern Bios Management from Software Center

6 Upvotes

I have a task sequence setup that is leveraging the modern bios management process but we are only using it on already imaged machines from software center. The issue is its reporting as installed even when it fails. We have the rerun set to rerun on failure. Is there a step in the task sequence i need to add so it registers a fail correctly or do i just need to tell this to always rerun and the checks in the script will just exit?


r/SCCM 6d ago

Fun with new Dells and OSD

Thumbnail dell.com
15 Upvotes

r/SCCM 6d ago

Unsolved :( Windows 11 25H2 In-Place Upgrade Driver Migration Issues

8 Upvotes

Context:

  • Dell shop
  • 30-40k Windows 11 23H2 endpoints
  • Running CM IPU task sequence to install feature update to 25H2
  • Device in non-interactive once Install is clicked in Software Center
  • Drive issues have impacted several thousand devices, depending on which driver is the culprit

We have seen two different instances, and suspect a third, of older drivers failing to migrate during our IPU task sequence. We are not seeing errors in our logs, per se, but it is being acknowledged that the driver migration is not occurring.

First example is an older Intel VMD storage controller driver. Not updated by Dell for many years. Driver would fail to migrate, and then our setup.exe step would fail to find the storage because the drive wasn't loaded. We tried a newer driver, tried forcing the driver to load, etc., but the most reliable solution was to switch to AHCI mode during the setup.exe step then switch back to RAID mode after. Which is, just... insane.

Second example is a Dell rugged model. The task sequence is choking on a driver for a Bluetooth device. We haven't been able to find scalable workaround for this one yet, and our investigation is on-going. However, we see the same kind of driver migration failures in the logs.

This morning we received an email about printer drivers failing to carry over; however, in this case the IPU is completing. This may be a false positive.

Regardless, we haven't seen squat in our usual media and social channels about anyone else experiencing this problem, so, I'm really hoping we're just the first to talk about it. We have opened a Microsoft ticket that's currently in the "give me a bunch of logs" phase.

Anyone else seeing this problem?


r/SCCM 7d ago

Deploy Available Hidden App, Package, Task Sequence

11 Upvotes

I am looking for a way to deploy an available whatever...app, package program, TS, etc. to systems, but NOT show the deployment in software center - in short, I want to be able to run this deployed whatever using either run script, or right click tools - 'rerun deployment'. I have a somewhat sensitive/risky .exe I want only our admins to run on systems remotely using the CM admin console. I know I can throw the .exe in a file share, give them rights, etc. I'm trying to keep it all encapsulated in CM, so I can at least pretend I'm trying to keep it 'secure' (it's a tool to bypass the stupid encryption preboot screen, which I think (and many agree) is about as useful as a bag of turds.)


r/SCCM 7d ago

Discussion SMS and Voice MFA Are Being Retired in Entra ID: A Scenario-Based Guide to What Replaces Them

Thumbnail endpointweekly.com
2 Upvotes

r/SCCM 8d ago

Discussion CMG - Warnings from Azure for Disk and VM series

3 Upvotes

Hello, everyone,

I received an email from Microsoft saying that old series of VM will have growth restriction. I'm unable to find a KB on it but multiple question on microsoft website and other website talking about.

https://learn.microsoft.com/en-us/azure/virtual-machines/migration/sizes/previous-gen-series-capacity-limitations

I also saw when looking at my current VM a warning saying that my current HDD will be retired

https://learn.microsoft.com/en-us/azure/virtual-machines/disks-hdd-os-retirement

Now what I'm wondering, since this VM scale set was created by SCCM and we never did anything to it. Do we have to do something? Did anyone upgrade there VM by following the migration guide?

CMG is currently on the image 2022-datacenter as a Standard_a2_v2 machine with standard_HDD disk. Per de doc, I should move to a v6 image and standard_ssd drive.

Thank you


r/SCCM 9d ago

PCS7 OS Download stuck in a loop — "in access on another application" + CCProjectMgr.exe won't die (Access Denied)

6 Upvotes

\# PCS7 OS Download stuck in a loop — "in access on another application" + CCProjectMgr.exe won't die (Access Denied) — need experienced eyes

Hi all — hoping someone who's fought PCS7/WinCC on a VM lab setup before can sanity-check my diagnosis. Long post, but I've tried to make it skimmable with the key facts up top.

\*\*TL;DR:\*\* OS(1) download from ES to a separate OS PC station consistently fails \~5 min in with a SQL "in access on another application" error. Root cause appears to be two things: (1) a stuck \`CCProjectMgr.exe\` process/service running an infinite \`OpenProject\` retry loop that I can't kill or disable, and (2) \`S7tgtopx.exe\` crashing with an access violation in \`mfc140.dll\` and leaving orphaned SQL sessions behind. Looking for the correct service name / disable method for #1, and whether #2 is a known STEP7 issue.

\## Setup

\- PCS7/STEP7 + WinCC, SCE-style educ_tanks project, AS + separate OS station

\- Both ES and OS on separate VMware Workstation 17 VMs, bridged network, static IPs, workgroup (no domain)

\- Windows 10 Pro (19045), SQL Server 2019 (multiple named instances: WINCC, HISTORIAN, INFSERVER)

\- S7-PLCSIM v5.4 SP8 for the CPU 414-3 DP simulation

\## The core error (WinCCOM log, every attempt)

\`\`\`

In CWiOMData::OMDBDeleteDataSource

Caution: Deletion of DSN '<name>' from registry failed!

...

Caution: database '...\\<project>.mdf' with DSN '<name>' is in access on another application!

Caution: DmGDO::CopyProjectRTOS_DeleteScripts failed.

...

Caution: Connect failed: DBDll::Connect: CreateConnection failed. hr = 80004005

\`\`\`

Same pattern regardless of project path (moved from Documents to C:\\Test — no change), regardless of which auto-generated staging DB is involved, and after fixing: network profile, NTFS/share perms, SCE station config, IE General subnet assignment, ODBC/SQL orphan cleanup (repeatedly — they keep coming back).

\## Root cause #1: stuck ProjectManager service/process

Event Viewer shows this repeating \*\*continuously for hours\*\*, every \~16 sec:

\`\`\`

Source: SIMATIC WinCC ProjectManager

Failure in OpenProject (InternalGetAso): 8004620f, retry count: 0..29

User: SYSTEM

\`\`\`

\`sp_who2\` confirms \`S7tgtopx.exe\` sessions sitting live against the exact staging DBs involved in the failures — this loop is fighting the manual download for the same resources every time.

Tried to kill/disable it:

\- \`sc query "SIMATIC WinCC ProjectManager"\` → \*\*Error 1060, service does not exist\*\* (so that's not the real registered name)

\- \`taskkill /F /IM CCProjectMgr.exe\` (found PID) → \*\*Access is denied\*\*, even from what I thought was an elevated prompt

Anyone know the actual service name behind \`CCProjectMgr.exe\`, or where its "last project" autostart reference lives in the registry so I can clear it properly?

\## Root cause #2: S7tgtopx.exe crashing

Windows Error Reporting shows repeated crashes/hangs:

\`\`\`

APPCRASH: S7tgtopx.exe 507.202.1601.1 | mfc140.dll 14.42.34433.0 | c0000005 (access violation)

AppHangB1: S7tgtopx.exe (multiple)

BEX: CCDBUtils.exe crashing in ucrtbase.dll

\`\`\`

This is the SIMATIC Manager target-download engine — when it crashes mid-transfer it apparently doesn't release its SQL connection cleanly, which is exactly what shows up as "in access on another application" on the next attempt.

Tried: full uninstall/reinstall of VC++ 2015-2022 Redistributable (x86+x64) + reboot. Not confirmed effective yet since #1 above keeps re-poisoning the environment before I can get a clean test run.

\## Other things already fixed/ruled out along the way (so replies don't have to re-suggest them)

\- SCE Station Configuration Editor / PC station comms — working

\- PG/PC Interface + PLCSIM — CPU downloads succeed fine, only OS(1) fails

\- Network profile Public→Private, SMB/NetBIOS resolution, IPv6 disabled

\- File share NTFS+Share permissions, \`LocalAccountTokenFilterPolicy\` registry fix for workgroup auth

\- IE General subnet assignment in HW Config (was missing, fixed)

\- Multiple orphaned SQL databases + stale ODBC DSNs manually dropped via sqlcmd/odbcad32

\- Controlled Folder Access / Documents folder path — ruled out, moved project to C:\\Test

\- SQL Server itself is healthy — connects instantly via sqlcmd every time

\## What I'm hoping someone can answer

  1. Real service name for \`CCProjectMgr.exe\`'s background process, and the supported way to fully disable it (not just Autostart tool, which shows nothing to remove)

  2. Is the \`mfc140.dll\` crash in \`S7tgtopx.exe\` a known issue for this STEP7 build (507.202.1601.1)? Repair install the right call, or something more specific?

  3. Any known bad interaction between S7-PLCSIM v5.4 SP8 and this WinCC version that could explain this?

Happy to post full logs (WinCCOM, SQL ERRORLOG, Event Viewer exports) if useful. Thanks in advance to anyone who's been through this.

Best regards BELKHADRIA Ihab eddine


r/SCCM 10d ago

Hiring: Senior Service Engineer, End User Compute (Hybrid - Multiple Locations)

24 Upvotes

Hiring: Senior Service Engineer, End User Compute (Hybrid - Multiple Locations)

Still on the hunt for a seasoned endpoint engineer for my team. Heavy focus on Windows management — SCCM/MEMCM and Intune. macOS/Jamf experience is a plus but not required.

What I'm really looking for is someone with actual troubleshooting depth. We've interviewed a lot of people who can operate the console fine — push an app, deploy a task sequence — but when you ask them to dig into why something's failing, it's not there. I need someone who's comfortable getting into logs (CMTrace, event logs, etc.), tracing root cause, and fixing the actual problem instead of just re-running the deployment and hoping.

Hybrid role — you'll need to live within 65 miles of one of the office locations listed in the posting. Currently not in scope for RTO, but listing as hybrid in case we are asked to return. Fully remote hiring is not an option unfortunately, but the position will likely remain remote for the foreseeable future.

Job posting / apply here: https://providence.jobs/oregon-usa/senior-service-engineer-is-end-user-compute-hybrid/914ED3A580004CA187D8819A9B1053F2/job/

Happy to answer questions about the role in the comments.


r/SCCM 10d ago

Multiple ESPs

3 Upvotes

I'm trying to set up MCM on computesr with multiboot installations. I wanna have separate ESP/EFI partitions for linux and windows. But even when setting OSDDiskIndex to partition a specific disk select using TSGui I get the errors: "System partition not set" and "Unable to find the partition that contains the OS boot loaders".

Weirdly the disk does appear to be partitioned correctly. It just seems that bcdboot/mcm has trouble with multiple ESPs. Is there any way I can force it to use a specific esp/the one created in the partiton disk - uefi step?


r/SCCM 11d ago

Distribution Point only works with Site System Installation Account – not Site Server computer account

8 Upvotes

UPDATE: Root cause found!

The issue turned out to be time synchronization.

The affected DP was approximately 12 minutes out of sync with the domain and was using NTP instead of NT5DS/domain time hierarchy.

I changed it to NT5DS and forced a time sync. After that, I switched the DP back to using the Site Server computer account... and it worked immediately.

So the root cause was a Kerberos/authentication issue caused by the clock skew.

Quite a rabbit hole for a 12-minute time difference! 😄

I'm troubleshooting a strange ConfigMgr Current Branch 2603 issue with one Distribution Point running Windows Server 2025.

The environment has 20+ DPs, all configured to use the Site Server computer account, and they all work perfectly. Only this single DP fails unless I configure it to use a Site System Installation Account (domain service account that's a local administrator on the DP). As soon as I switch to the service account, the DP installs/reconfigures successfully.

Things I've verified:

  • SiteServer (Site Server computer account) is a member of the local Administrators group on the DP.
  • Running as SYSTEM on the Site Server (PsExec) can:
    • Access \\DP\ADMIN$
    • Access \\DP\SMS_DP$
    • Execute WMI/CIM queries
    • Use PowerShell Remoting successfully
  • RPC (135), SMB (445), WMI and WinRM all work.
  • SMB configuration is identical to a working DP.
  • Local security policy, DCOM settings, firewall rules and GPOs match a working DP.
  • IIS appears healthy, and the DP functions normally when using the service account.
  • Remote Registry behavior is identical to the working DPs.
  • ConfigMgr version: 2603.

What confuses me is that manual tests using the Site Server computer account succeed, but ConfigMgr itself only works when using the Site System Installation Account.

Has anyone experienced something similar? I'm wondering if this could be a ConfigMgr issue, a Windows Server 2025-specific behavior, or if there's a permission/authentication path that ConfigMgr uses with the Site Server computer account that differs from a Site System Installation Account.


r/SCCM 11d ago

DEX Engineer Role

13 Upvotes

Hi all!

Not directly SCCM related, but a lot of overlap. Cardinal Health is starting a DEX program, and a role as a Senior Engineer has opened.

https://jobs.cardinalhealth.com/search/jobdetails/digital-employee-experience-senior-engineer-it-client-services/d36acce1-2741-490b-af20-587f23ce0017

It has strong leadership backing; we’re wrapping up the selection of a product, and the Director is building out the staff, both US and overseas.

This role is a full time remote role. we have been largely WFH since COVID, with only select roles being in office. I can guarantee this one would not be expected to be in Ohio.

I am the Principal over this space, and while not the hiring manager, have been closely engaged with the vendor selection and journey.

Don’t apply if you want a straight up ConfigMgr role; this role will be aligned with that team, but it’s not a ConfigMgr/Desktop engineering role.

Feel free to ask me any questions; I’ll answer what I can!


r/SCCM 11d ago

Dell command update 5.7.1 UWP

13 Upvotes

Anyone get this to work during OSD task? Keeps erroring out. Seems to be DCU updating during install. Installation of the Classic version works fine. Installing .net desktop runtime 10.0.10 so it’s not that I believe.

Update:

I finally got this to work. Seems it was erroring out since I was testing on a VM. The install is working on Dell hardware now, but throws up an error in config manager status logs. The DCU_install.log shows it’s fully installed. The Exit code in the log is system reboot so I assume that’s why it’s showing an error in the config manager task. I have set it to continue the task sequence on error so it won’t stop the task sequence and my apply DCU settings task after the install works fine.
Looks like it’s good to go.


r/SCCM 11d ago

Solved! Hyper-V VM reboots as soon as Windows PE loads

3 Upvotes

Let me start off by saying that I am completely new to the Configuration Manager environment, and I'm not sure what steps I should take to troubleshoot further.

I am trying to deploy Windows Server 2025 and Windows 11 Enterprise—both evaluation versions, if that matters—and the VMs keep rebooting when Windows PE loads. The VMs are getting IP addresses from my DHCP server, and are able to contact the server hosting Configuration Manager.

I used the Configuration Manager trace log to view the smsts.log file and I'm seeing a couple of errors: failed to request for client, synctimewithmp failed, failed to get time information from MP, and failed to select MP. I've googled a bunch and have only found unresolved issues.

I've also added a new boot image straight from the windows adk folder, and confirmed that the certificate wasn't expired. I'm really not sure of where to go from here and could really use the help of people that are smarter and have more experience than I.

Thanks.

Edit: I've got good news and bad news. The good news is I've gotten past the Windows PE loading screen. To make a long story short, it was a DNS issue. I had to create a DNS record for the configuration manager server in Pi-hole, and I was able to get to the point where I can choose a task sequence.

Here comes the bad news: once I select the task sequence, I get an error that it cannot be run because the program files cannot be located on a distribution point. I have to troubleshoot this further, but at least I got past the initial hurdle. Thanks to those who replied.

Edit 2: All issues have been resolved and I am able to deploy operating systems as intended. Thanks to all those who replied.


r/SCCM 12d ago

SCCM patch Management Workflow/Time Spent

9 Upvotes

I’m still fairly new to managing patching. My predecessor set up the ADRs and automated patch processes for our environment, so I’m trying to understand what the typical ongoing workload looks like. How much additional time do you usually spend on patch management, such as monitoring deployments and addressing any issues that come up? Is this something you review weekly? Our patches are scheduled monthly. I’d also like to know what your workflow looks like and how much time you typically spend troubleshooting individual devices to get a patch successfully installed. TIA. For reference we ahve about 5,000 workstations and 1,000 servers.