SCCM: Software Updates: Automatic Deployment Rules

Roberto 646 Reputation points
2021-04-01T09:26:34.823+00:00

Hello.

I setup a couple of ADRs.
They run successfully and correctly update SUGs and DPs.
Problem is that clients don't get the updates even though they are in the relevant collection.

Can somebody help me debug and fix this?

Thank you and best regards.

Microsoft Security | Intune | Configuration Manager | Other
0 comments No comments
{count} votes

Answer accepted by question author
  1. Rahul Jindal 11,511 Reputation points
    2021-04-01T12:49:03.783+00:00

    Are the clients not installing the updates or not evaluating the updated assignments?


7 additional answers

Sort by: Most helpful
  1. Roberto 646 Reputation points
    2021-04-07T09:04:58.27+00:00

    Hi @Amandayou-MSFT
    Hi @Kalyan Sundar
    Hi @Rahul Jindal

    The situation now is as follows:
    Clients get the updates included in one UG (Windows 10), but still have the following problems:

    1. Clients also get other updates not included in any UGs but present in "All Software Updates"
    2. Seems that Endpoint Protection don't get any updates

    Maybe what I include in the "Endpoint Protection" UG and on WSUS is not what clients need to update their security?
    What do I need to put on the Endpoint Protection UG for updating the security intelligence and definitions on clients?

    85127-20210407atest-01about-windows-security.jpg
    85185-20210407btest-01installed-updates.jpg
    85248-20210407csccmug-enpoint-protection.jpg
    85235-20210407dsccmug-windows-10.jpg

    Any more hints?

    Thank you and best regards.
    Roberto


  2. Roberto 646 Reputation points
    2021-04-08T12:53:30.66+00:00

    Hi @Amandayou-MSFT
    Hi @Kalyan Sundar
    Hi @Rahul Jindal

    Now that in "All Software Updates" are present the Windows Defender updates, the client somehow gets them even though these updates are not in any UG. That's good because something works, but very bad because any client can get anything it finds on the WSUS. I don't want that. Client must not take any update directly from WSUS, but only SCCM ADRs puts in UGs for them.

    How to do I fix that? I want that clients only take what is in UGs associated with collections that includes those clients.

    Thank you and best regards.
    Roberto


  3. Roberto 646 Reputation points
    2021-04-22T13:16:53.61+00:00

    Hi @Amandayou-MSFT
    Hi @Kalyan Sundar
    Hi @Rahul Jindal

    Sorry I'm late in answering, but had to work on other tasks.

    Problem is not fixed because clients gets any update they want directly from WSUS and not only what is in UGs.

    For now I disabled the sync on a schedule of SUP and now clients don't get any update anymore. I will go back to work on this later on, after lessons and exams will be over because I don't want to risk hundreds of clients again go BSOD during exams because of updates like the recent kb5000808.

    I will anyways Accept answer from @Rahul Jindal as he helped me find the conflicting GPO and debugging the problem.

    One more question though:
    When I configure Software Update Point Component Properties, I see in Sync Settings: "Synchronize from Microsoft Update". Does that refers to SCCM or WSUS? I believe WSUS, because everything I set here I usually find it later in WSUS, but I'd like your opinion.

    Thank you and best regards.
    Roberto


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.