SCCM - can you find out who did what in SCCM Console?

MTrn 481 Reputation points
2021-10-15T15:34:23.533+00:00

Hi,
Something strange happened last night and I am trying to get to the bottom of it.
I have a Windows 10 In Place Upgrade collection - membership rule type is Direct
I have a remote site named HOP, which has a collection named "All HOP Computers". This collection has all workstation and servers, every device belonging to this site is in the collection.
IT personnel have been manually adding computers to the Windows 10 IPU collection for the win10 upgrade.
Last night, I had to redistribute the Win10 Upgrade package to HOP DP.
All of a sudden late in the night, ALL computers in HOP were getting the windows 10 upgrade.
While investigating what happened that triggered the mass upgrade, I found that somehow the All HOP Computers collection was added to the Windows 10 IPU membership as shown below.

Are there any ways I can find out how this collection made its way into the Win10 IPU collection?

Thank you so much!

140951-image.png

Microsoft Configuration Manager
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. MTrn 481 Reputation points
    2021-10-15T17:43:04.627+00:00

    @Ilia Ershov and @Garth Jones

    Thank you for your responses. Yes, I did try to look at those status messages but all they showed was "User so and so modified the Collection Properties for a collection named "Windows 10 In-Place Upgrade" . This collection is currently assigned to the following ConfigMgr Administrators: "

    That was all.

    1 person found this answer helpful.

  2. Ilia Ershov 126 Reputation points
    2021-10-15T17:01:41.05+00:00

    You can investigate status messages. They contain related information about collections: who created, modified and deleted.
    Reffer the following article

    0 comments No comments

  3. Garth Jones 1,656 Reputation points MVP
    2021-10-15T17:04:13.22+00:00

    The audit events should tell you.

    0 comments No comments

  4. MTrn 481 Reputation points
    2021-10-20T23:37:06.447+00:00

    @Garth Jones and @Ilia Ershov

    We just had another incident and I am cracking my head trying to understand what is causing this.

    I just created a new collection named "Exclaimer Cloud Agent" to push out the Exclaimer app. This collection includes the Windows 10 collection and excludes several other collections. A few hours later I was made aware that serveral windows 10 got the Windows 10 IPU upgrade. I went into the properties of the IPU collection and guess what? The Exclaimer collection was added to the IPU collection!!!!!!!!!

    I really don't know what is going on!! If you say CM itself cannot add/remove devices, why this happened a 2nd time? Could it be that the inclusion/exclusion of the collections screwed this up? Because those windows 7 computers were upgraded to windows 10, they are now part of the Windows 10 collection. Could it be that because I included the Windows 10 collection in the Exclaimer collection that it automatically added itself into the IPU collection?

    For any computers that were successfully upgraded to Windows 10, should I remove them from the IPU collection to hopefully avoid this in the future?

    0 comments No comments