UpdatesDeployment.log - Definition Updates - System Center Endpoint Protection

Duchemin, Dominique 2,006 Reputation points
2023-02-11T03:38:18.5566667+00:00

Hello,

Apparently the system center endpoint protection agent is not getting updated from Configuration Manager:

Fallbackorder: InternalDefinitionUpdateServer|MicrosoftUpdateServer|MMPC

We are NOT patching the server using Configuration Manager Software Update Point servers VRPSCCMSU01 or DGIT-SU-SCCM-P1.

We are patching the server with the regular WSUS process using the server VOPWSUS2K12.

I checked the UpdatesDeployment.log and I saw this error looping ... Any idea?

Thanks,

Dom

Assignment {d630002c-e648-432d-9b79-5766f605206e} has total CI = 14	UpdatesDeploymentAgent	2/10/2023 6:49:12 PM	7704 (0x1E18)
Message received: '<?xml version='1.0' ?>
	<CIAssignmentMessage MessageType='EnforcementDeadline'>
	    <AssignmentID>{d630002c-e648-432d-9b79-5766f605206e}</AssignmentID>
	</CIAssignmentMessage>'	UpdatesDeploymentAgent	2/10/2023 6:49:12 PM	168 (0x00A8)
GetUpdateInfo - failed to get targeted update, error = 0x87d00215.	UpdatesDeploymentAgent	2/10/2023 6:49:12 PM	7704 (0x1E18)
OnPolicyModify for assignment ({d630002c-e648-432d-9b79-5766f605206e})... 	UpdatesDeploymentAgent	2/10/2023 6:49:12 PM	7704 (0x1E18)
Starting forced trigger (TriggerEnforce) for assignment {d630002c-e648-432d-9b79-5766f605206e}	UpdatesDeploymentAgent	2/10/2023 6:49:12 PM	7704 (0x1E18)
Detection job ({41D3C1DC-D4F6-4699-9EC5-F3E2BE540222}) started for assignment ({d630002c-e648-432d-9b79-5766f605206e})	UpdatesDeploymentAgent	2/10/2023 6:49:12 PM	7704 (0x1E18)
Unable to find CCM_PrePostActions.SiteSettingsKey=1.	UpdatesDeploymentAgent	2/10/2023 6:49:12 PM	7704 (0x1E18)
Orchestration lock is not required.	UpdatesDeploymentAgent	2/10/2023 6:49:12 PM	7704 (0x1E18)
Deadline received for assignment ({d630002c-e648-432d-9b79-5766f605206e})	UpdatesDeploymentAgent	2/10/2023 6:49:12 PM	168 (0x00A8)
Enforcement action already in progress	UpdatesDeploymentAgent	2/10/2023 6:49:12 PM	168 (0x00A8)

Microsoft Configuration Manager
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 10,781 Reputation points MVP
    2023-02-11T06:46:57.0333333+00:00

    Has this ever worked? Endpoints will expect WSUS source to be the SUP for SCEP.

    0 comments No comments

  2. Duchemin, Dominique 2,006 Reputation points
    2023-02-12T02:04:00.1566667+00:00

    Hello,

    I don't think it has ever worked. The results were not expected but due to the fallbackorder "InternalDefinitionUpdateServer|MicrosoftUpdateServer|MMPC"

    settings another WSUS server (the original one not SUP) would have taking over...

    Any idea why Microsoft proposed this solution if the SUP is mandatory and we do not use them for servers?

    Thanks,
    Dom

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.