Without deeper investigation here, not much can be said but my initial thought is similar to @Garth Jones 's comment and would result in duplicate GUIDs and other negative ramifications. Basically, are you sure these systems were built with a properly sysprepped image? Alternatively, do the devices all share a single common PKI-issued client authentication certificate?
APPLICATIONS DEPLOYING TO MACHINES NOT IN COLLECTION AND MORE
So let me set the scenario best I can. We have 1 site with 2 servers the main server running 2006 with the latest hotfix rollup applied. The other is an IBCM external management point server. What we have noticed is the following behavior
- Machines stop showing up all together within the Configuration Manager even thought hey have the agent installed and it is pointed correctly.
- After a discovery is ran (Against AD) the machines will show back up but show they have never had an agent installed
- If you reinstall the agent the machines will go away again.
- Using direct rules to build a collection and then deploying an application the application is being pushed out to multiple computers that are not within the collection. We know they are being pushed out because the application we are installing as a dashboard that shows computers installed it etc
- A computer that is supposed to be in the collection disappears and is replaced by another one that is NOT in the direct rule for the membership.
- The computer displayed incorrectly in the collection is on a different subnet and it shows the incorrect primary user as well as the incorrect currently logged on user
Any help/guidance etc would be amazing. This is a new environment we have been standing up over the last month so it is very possible we might have missed something etc
Microsoft Security Intune Configuration Manager Other
-
Jason Sandys 31,406 Reputation points Microsoft Employee Moderator
2020-11-11T20:15:12.823+00:00
3 additional answers
Sort by: Most helpful
-
Garth Jones 2,076 Reputation points
2020-11-11T20:04:25.277+00:00 What exactly do you mean by #3?
Are the computer cloned?
Have you checked for Duplicate GUIDs? -
Sherry Kissinger 5,526 Reputation points
2020-11-12T00:59:03.303+00:00 I have a different question; around "computers disappear"--then reappear after you re-discover them with Active Directory System Discovery.
I'm wondering what Discovery Agents you have enabled? Just/only AD system Disc? What about heartbeat?
"in general", I tell people that daily heartbeat is fine; if you don't have that at daily, or not enabled at all, what was the technical reason to disable heartbeat? I believe "out of the box" heartbeat is enabled for simple, weekly; but we don't know what you might have done.
-
Simon Ren-MSFT 40,341 Reputation points Microsoft External Staff
2020-11-12T06:53:55.683+00:00 Hi,
Thanks for posting in Microsoft MECM Q&A forum.
When using PKI, by default the SCCM agent generates a Client GUID based on a certificate in the personal Computer store. As Jason mentioned, please make sure that they don't use the same Client authentication certificate. In your scenario, every machine should has its own certificate from GoDaddy.
Best regards,
Simon
If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.