Windows 10 ,Feature Update to 1909, Certificates missing after

Walsh, Liam 36 Reputation points
2020-10-22T14:50:00.337+00:00

Any one seen this issue ,only occurring in about the last week. It maybe a wider issues globally. Not sure what triggered it.
Basically in the last few days some updates from 1809 to 1909, after completed, the local laptop certs are missing. Which is a problem for all our home users on VPN! (i.e. with covid still around)

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
10,528 questions
Windows 10 Setup
Windows 10 Setup
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Setup: The procedures involved in preparing a software program or application to operate within a computer or mobile device.
1,899 questions
0 comments No comments
{count} votes

23 answers

Sort by: Most helpful
  1. Rahul 1 Reputation point
    2020-10-28T10:54:58.833+00:00

    Yes, i also confirm this issue has impacted around 300+ machines in my environment, Certificates are missing post 1909 upgrade on top of Oct month patch. Additionally SAP app is broken and we have to reinstall it to fix the login issue.

    0 comments No comments

  2. Jayson Gabler 1 Reputation point
    2020-10-29T00:57:34.643+00:00

    This has just happened to me. I applied the 20H2 feature update and after the reboot, the laptop showed the "no internet" symbol in system tray. At first, I thought the WLAN driver was incompatible with 20H2 but I checked Device Manager and it was still there. Then I noticed the wireless networks were still "available", but when I tried to connect to the usual one, I got an error about needing a certificate.

    So finally I checked the local machine certs, and lo and behold, all the certs in the Personal store had disappeared!

    0 comments No comments

  3. Su, Steven S 21 Reputation points
    2020-10-29T04:04:58.683+00:00

    Is there any news update? I also encountered the same problem; there is no solution at present, please help!!


  4. RK-0561 1 Reputation point
    2020-10-29T06:01:11.487+00:00

    I can also can confirm the issue.

    Windows 10 Enterprise x64 Edition, we are updating from 1809 to 1909 using the SCCM Upgrade Task Sequence.

    Clients with the "2020-10 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB4577668)" will fail if connected with VPN (wireless) during the update to 1909.

    Computer Personal Certificates Store is empty, all certificates are missing, certificate chain broken.


  5. Joy Qiao 4,886 Reputation points Microsoft Employee
    2020-10-30T05:40:10.16+00:00

    Hi,

    Config Manager customers that currently use or can switch to Task Sequence workflow can use the following steps to add 2020 10B updates to target OS image:

    Below are the solutions for certs not migrating during an in-place upgrade when using ConfigMgr:

    1) Use Scheduled Updates in ConfigMgr to add in the required updates to the Operating System Upgrade Package. This is basically offline servicing and updates install.wim in the Operating System Upgrade Package with the updates. This currently is the most straightforward solution which should work in all environments.

    2) Download the latest Windows 10 ISO dated October 2020 or newer. Use the files from this ISO to replace the files from the current Operating System Upgrade Package by deleting all content from the source directory of the Operating System Upgrade Package and then replacing with the contents from the ISO. After updating the content update DPs.

    3) At the Upgrade Operating System task, select the option Dynamically update Windows Setup with Windows Update and the sub-option Override policy and use default Microsoft Update. This technically is the easiest solution but requires that clients have access to the public Microsoft Update site. If you block access to the public Microsoft Update site this may not be a viable option for you

    4) If you do not have access to the public Microsoft Update site, at the Upgrade Operating System task, select the option Dynamically update Windows Setup with Windows Update but do not select the option sub-option Override policy and use default Microsoft Update.

    This will attempt to grab the dynamic update from the local WSUS server. This gets a bit trickier since the update needs to be approved and downloaded on the WSUS server itself. Notice, it means the WSUS server and not the ConfigMgr SUP/DPs. Windows Setup has no concept of ConfigMgr so it will only try to go to the WSUS server. This means content is downloaded from the WSUS server and not from DPs. For environments that have only one or a few WSUS server, this means ALL clients will go to that WSUS server and download content from that WSUS server. This might possibly overload the WSUS server. Additionally the dynamic updates will need to be manually imported into WSUS from the Microsoft Update Catalog site.

    5) You can manually apply the dynamic update directly to the Upgrade Operating System Package:

    a) Download the dynamic update from the Microsoft Catalog site

    b) Extract the contents of the cab

    c) Copy the contents from the cab into the source directory for the Upgrade Operating System Package, overwriting any files

    d) Update DPs for the Operating System Upgrade Package

    For options 4 & 5 when searching for the applicable dynamic update at the Microsoft Update Catalog site, search for the term Dynamic Update for Windows 10 Version 2004 and select the update dated 2020-10 or newer.

    Related links:

    Microsoft Update Catalog

    Apply Software updates to an image

    Manage OS upgrade packages with Configuration Manager

    Create a task sequence to upgrade an OS in Configuration Manager

    Upgrade Operating System

    Dynamically update Windows Setup with Windows Update

    Override policy and use default Microsoft Update

    Import updates from the Microsoft Update Catalog

    Bests,

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.