SCCM Software Updates (concerned & confused) - Deployment status show computers compliant but they are actually not

MTrn 481 Reputation points
2021-07-13T16:06:41.267+00:00

I am confused and concerned at the same time.

I have a Software Update Group for the PrintNightmare July 6 OOB patch. This group contains a mix of Windows versions (shown in screenshot). The Patch group was deployed to a small group of computers as a test.

114275-image.png

When I checked the Deployment Status, some computers showed as "Compliant", yet, they did NOT have the July patch installed. So we manually clicked "Check online for MS Updates" in Update & Security on those computers, the July patch showed up in the list.

I am confused because if the computers did not have the patch, why did SCCM showed them as "compliant"? Those computers were not even listed in the list of "required" for the the patch.

What could explain this? I am concerned that if I trust SCCM to tell me my clients are "compliant", yet in reality they don't have the patch installed unless manually check for updates, this could be trouble. Maybe there is some explanation for this?

Thank you!

Microsoft Configuration Manager
0 comments No comments
{count} votes

Accepted answer
  1. Amandayou-MSFT 11,046 Reputation points
    2021-07-14T03:16:53.797+00:00

    Hi @MinaTran-2950,

    First, we should notice the update installed from 'check online for MS Updates' is same as from SCCM.

    If so, the above situation occurs, it seems that there is scanning wrong between SCCM server and client. We should check if any error in UpdatesHandler.log, it records details about software update compliance scanning and about the download and installation of software updates on the client.

    What could explain this? I am concerned that if I trust SCCM to tell me my clients are "compliant", yet in reality they don't have the patch installed unless manually check for updates, this could be trouble. Maybe there is some explanation for this?

    Under normal circumstances, if the update is required by these clients, those computers will be listed in the list of "required" for the the patch.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 additional answers

Sort by: Most helpful