SCCM local group policy

Tyler Horton 1 Reputation point
2020-11-17T21:58:22.67+00:00

My organization has recently begun piloting Intune. Currently our devices are co-managed and we have set our sliders to Intune for devices in the test collection. My question comes in the form of the local group policy management that happens when the SCCM client checks in. An enabled local GPO (Computer > Admin templates > Windows Components > Windows Update > Specify intranet Microsoft update service location) causes an error when checking for updates through Intune (WUfB). The only way updates come through reliably are if that local policy is disabled, or we make a registry change to allow connection to Windows Update internet locations.

I have been searching online to see if there is a way to disable that local policy from being set on the devices in our test collection. I'm coming up with answers that point to no. Can anyone provide insight on what a best practice would be in this case or share workarounds?

Thanks

Microsoft Security | Intune | Configuration Manager | Other
0 comments No comments
{count} votes

9 answers

Sort by: Most helpful
  1. Jason Sandys 31,411 Reputation points Microsoft Employee Moderator
    2020-11-18T01:36:55.417+00:00

    Sorry, I'm a bit confused. What exactly is your intent here for updates? Using ConfigMgr or using WUfB?

    If WUfB, then the local group policy created by ConfigMgr does not in any way interfere with this. However, if you want to use WUfB, you must open access to the Internet by the clients as that's the entire point of WUfB.

    0 comments No comments

  2. Tyler Horton 1 Reputation point
    2020-11-18T14:45:42.777+00:00

    Thanks for the reply. I'll clarify - we want to use WUfB, however the clients that we are piloting Intune on are co-managed and still check in with ConfigMgr. SCCM appears to be setting the local group policy and corresponding registry setting Do not connect to any Windows Update Internet locations. With this enabled, WUfB fails. Is there another way to circumvent this aside from uninstalling the SCCM client? We have other clients that still are receive updates exclusively from WSUS and I don't want to break that functionality for the other clients by changing any task sequence settings.


  3. Jason Sandys 31,411 Reputation points Microsoft Employee Moderator
    2020-11-18T15:14:33.13+00:00

    SCCM appears to be setting the local group policy and corresponding registry setting Do not connect to any Windows Update Internet locations

    ConfigMgr does not do this. If this is configured in your environment, it is not coming from ConfigMgr. You need to find whatever is setting this and adjust accordingly.


  4. Tyler Horton 1 Reputation point
    2020-11-19T15:38:16.507+00:00

    I must be the one who is confused then. When setting ConfigMgr client settings and the option 'Enable software updates on clients' is Yes, does it not apply local group policy to enable an intranet site for SCCM updates?


  5. Rahul Jindal [MVP] 10,911 Reputation points MVP
    2020-11-19T22:33:29+00:00

    What does the co-management capability say for the endpoint? Also, what is the dual scan status value in the registry of the endpoint? Are you certain that the Windows Update work load is switching to Intune?


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.