Task Sequence: xxxxxxx has failed with error code (0x80070002) SCCM

Dilan Nanayakkara 1,111 Reputation points
2020-09-10T13:21:32.037+00:00

Hi All,

I am facing the Issue "Task Sequence: xxxxxxx has failed with error code (0x80070002) in the task sequence step ''Configure Secure Boot". However my machine will pxe boot successfully and appeared the task sequence wizard.

we have enabled HTTPS in our Distribution Settings and further that is an additional DP in our environment. then I have checked the Network Access account settings and it was set to use computer account but I have added few user accounts which are already existing in our SCCM environment. however I am not sure whether these accounts should have access to our task sequence or not since I am not the person who created this TS. again, one thing I noticed, when I checked IIS settings of the additional DP where from pxe boot is still set to http bindings and webserver certificate is not under personal certificate either. however I am not sure this certificates is related to my problem since pxe boot is successful and error is showing up middle of the task sequence wizard.

appreciate the help to sort this out.

23787-2020-09-10-22-30-59.jpg

23803-2020-09-10-22-53-53.jpg

23804-2020-09-10-22-55-11.jpg

23845-2020-09-10-22-57-40.jpg

23815-2020-09-10-22-44-59.jpg

Thanks,
Dilan

Microsoft Configuration Manager Deployment
Microsoft Configuration Manager Deployment
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Deployment: The process of delivering, assembling, and maintaining a particular version of a software system at a site.
923 questions
0 comments No comments
{count} votes

Accepted answer
  1. Simon Ren-MSFT 31,601 Reputation points Microsoft Vendor
    2020-09-21T02:57:58.56+00:00

    Hi,

    Thanks you very much for your sharing and feedback. We're glad that the question is solved now. It may help others who have similar issue. Here's a short summary for the problem.

    Problem/Symptom:
    "Task Sequence: xxxxxxx has failed with error code (0x80070002) and 0x800700a1.

    Solution/Reason:
    "Clear Required PXE Deployments" from Unknown Computers and try again

    It's appreciated that you could click "Accept Answer" and upvote it, this will help other users to search for useful information more quickly. Thanks again for your time!

    Best regards,
    Simon

    0 comments No comments

4 additional answers

Sort by: Most helpful
  1. John Marcum - MVP 6 Reputation points
    2020-09-10T19:42:22.567+00:00
    1. The IIS screen shot shows no bindings for HTTP (443)
    2. When operating in HTTPS mode, I think you have to add the cert to WinPE
    0 comments No comments

  2. Simon Ren-MSFT 31,601 Reputation points Microsoft Vendor
    2020-09-11T02:59:33.537+00:00

    Hi,

    1. As with all task sequence issues and troubleshooting, it's firstly recommended to examine the smsts.log on the target system. Please refer to the following article to export the smsts.log to troubleshoot the task sequence error:
      SCCM: How to copy SMSTS.log when a Task Sequence fails
    2. When you have an environment with HTTPS only, the client must have a valid certificate for the client to communicate with the site and for the deployment to continue. Please import the Client authentication certificate to the site systems that have a PXE-enabled distribution point installed. For more information, please refer to:
      PKI certificate requirements for Configuration Manager

    Thanks for your time.

    Best regards,
    Simon
    If the response is helpful, please click "Accept Answer" and upvote it.


  3. Simon Ren-MSFT 31,601 Reputation points Microsoft Vendor
    2020-09-14T09:38:36.86+00:00

    Hi,

    Thanks for your reply.

    The error code 0x800700a1 means "The specified path is invalid." Based on my experience, the certificate we should import is not a DP certificate, it's a the client certificate for distribution points. This certificate has two purposes:

    1. It authenticates the distribution point to an HTTPS-enabled management point before the distribution point sends status messages.
    2. When the Enable PXE support for clients distribution point option is selected, the certificate is sent to computers. If task sequences in the operating system deployment process include client actions like client policy retrieval or sending inventory information, the client computers can connect to a HTTPS-enabled management point during the deployment of the operating system.

    For more detailed steps about how to import this certificate, please refer to:
    Deploying The Client Certificate For Distribution Points

    Best regards,
    Simon
    If the response is helpful, please click "Accept Answer" and upvote it.


  4. Simon Ren-MSFT 31,601 Reputation points Microsoft Vendor
    2020-09-16T09:11:22.67+00:00

    Hi,

    Thanks for your detaied information.

    Based on my understanding, the SCCM environment is in HTTPS only, and the situation we face are as below:

    1. Everything works well including PXE boot, when you unblock the two certificates with start date as a 11/09/2020.
    2. When you block the two certificates, only PXE boot fails, other functions are working fine.

    If I don't misunderstand, the two certificates with start date as a 11/09/2020 are used not only for site systems that have a distribution point installed but also for Boot images for deploying operating systems. The situation is as expected, we should not block these two certificates. When we have an environment with HTTPS only, the client must have a valid Boot images for deploying operating systems certificate for the client to communicate with the site and for the PXE OSD deployment to continue.

    And the PXE-enabled DP also need a certificate for Site systems that have a distribution point installed to communicate with HTTPS-enabled management point. The requirements for this Boot images for deploying operating systems certificate are the same as the server certificate for site systems that have a distribution point installed. Because the requirements are the same, so we can use the same certificate file.

    25155-cert1.png

    25136-cert2.png

    If I have misunderstood anything, please don't hesitate to let me know.

    Best regards,
    Simon

    If the response is helpful, please click "Accept Answer" and upvote it.