Edit

Summary of changes in Configuration Manager current branch, version 2609

Applies to: Configuration Manager (current branch, version 2609)

Summary of KB2377842

Release version 2609 of Configuration Manager current branch contains fixes and feature improvements. The "Issues that are fixed" list isn't inclusive of all changes. Instead, it highlights changes the product development team believes are most relevant to the broad Configuration Manager customer base. These changes were made in response to direct customer feedback about product issues and improvements.

Notes

Issues that are fixed

Security improvements

  • This release includes security improvements across multiple Configuration Manager components. It also includes the security fixes from the hotfixes included in this release.
  • CMPivot can fail on devices where the device-level PowerShell execution policy is set to AllSigned and the CMPivot signing certificate isn't trusted. The Configuration Manager client now trusts the signing certificate without requiring an administrator to manually deploy it.
  • Configuration Manager no longer requires the TRUSTWORTHY database property to load its SQLCLR assemblies and verifies that they are Microsoft-signed. For configuration requirements, see SQLCLR assembly trust.
  • A new upgrade prerequisite warning identifies sites configured to Automatically approve all computers (not recommended). This option is planned for removal in a future release because of security concerns. We strongly recommend switching to manual approval or automatic approval for computers in trusted domains as soon as possible.

Cloud management gateway

  • Shared key access is automatically disabled for cloud management gateway (CMG) storage, even if you haven't previously selected the option to disable it in the console.
  • Secrets created or updated by a cloud management gateway in Azure Key Vault can lack expiration dates, causing noncompliance with Azure policies that require secret expiration dates.
  • BITS uploads through a cloud management gateway can remain stuck for days after a connection interruption between the cloud management gateway connection point and management point. The connection point returns a generic HTTP 500 error instead of the specific BITS error needed for the client to restart the upload. Affected uploads can include inventory data and state message resynchronizations, delaying updates to the site's client information.
  • When you provision a cloud management gateway and select an existing Azure resource group, Configuration Manager can remove the resource group's tags. In environments with Azure policies that require these tags and deny their removal, CMG provisioning can fail. The console and New-CMCloudManagementGateway cmdlet also don't validate that the existing resource group and CMG are in the same Azure region.

Content management

  • Clients can fail to locate peer cache sources when partial content downloads are enabled. The following error is recorded:

    Procedure or function 'MP_GetSuperPeerContentLocations' expects parameter '@ClientLocationInfo_', which was not supplied.

  • On distribution points that use a Cryptography API: Next Generation (CNG) certificate, repeated content validation runs can leave additional private-key files on disk, increasing disk space usage over time.
  • Starting in Configuration Manager version 2503, a package download might not resume after a transient network failure. The deployment report can then incorrectly show a content mismatch error even though the content is valid.
  • The distribution point WMI provider can crash when creating an IIS virtual directory if the required IISWebSiteName registry value is missing. The operation now reports a failure instead of crashing the provider.

Client

  • Configuration Manager client upgrades can fail with error 1603 and an MsiExec.exe crash when a running process has more than 1,000 modules loaded.
  • Co-managed devices with Microsoft Entra user accounts can resend unchanged compliance state messages every hour when the Compliance policies workload is managed by Intune, causing a state message backlog.
  • On Configuration Manager client devices where User Account Control (UAC) is set to Notify me only when apps try to make changes to my computer, the UAC prompt can become unresponsive after you select Configure Settings in the Configuration Manager control panel.

Endpoint Protection

  • The Configuration Manager console and the Set-CMAntimalwarePolicy cmdlet can reject valid Microsoft Defender Antivirus contextual file and folder exclusions.
  • Antivirus exclusion settings deployed through Intune to tenant-attached Windows Server devices can remain on the devices after the policy is removed.
  • On co-managed workstations with the Endpoint Protection workload managed by Intune, Configuration Manager can remove Intune-configured Microsoft Defender Antivirus cloud block level and cloud extended timeout settings during policy processing.
  • After you export and import an antimalware policy, the Run a daily quick scan on client computers setting can change from No to Yes.

BitLocker management

  • MBAM-Web event logs can be missing or fail to record events after installing the Configuration Manager BitLocker management websites. The event logs are now registered correctly so that website events are available in Event Viewer.

Site systems

  • Message Processing Engine statistics updates and cleanup of processed messages can fail with an arithmetic overflow when a large volume of message data accumulates, after which the Message Processing Engine no longer processes data.
  • Passive site server promotion can remain in the Promoting state or report a boot image validation failure when the SMS Provider is installed only on remote servers.
  • Secondary site installation or recovery can fail with an sms_bootstrap.exe crash when the setup configuration data exceeds 10 KB.
  • Data warehouse synchronization failures can leave duplicate records for deleted items.
  • A service connection point installed on a remote server can fail to save Azure event details because of a database permission error.
  • Configuration Manager performance counters can be unavailable on a Windows Server 2025 primary site server or management point.
  • The Configuration Manager console can incorrectly display both Total space and Free space as 0 bytes for remote management points after the SMS_Executive service or the SMS_SITE_SYSTEM_STATUS_SUMMARIZER component restarts.
  • Removing the reporting services point site system role doesn't uninstall the Configuration Manager Reporting Services Point component, which can prevent the role from being reinstalled.
  • Management points in large environments can become unresponsive when TPM session limits are reached while processing client requests.
  • Site component and content-distribution operations can fail to connect to the site database when a site system installation account is configured, particularly for site systems in untrusted domains.
  • After promoting a passive site server, the console can continue to show Validate boot image (x64) package as in progress even though validation has completed.
  • Configuration Manager setup can unexpectedly close while moving the site database or installing a site when SQL Server startup parameters use large numeric suffixes.

Discovery

  • Heartbeat Discovery can corrupt multibyte characters in the System OU Name reported by clients, particularly in Japanese, Korean, Traditional Chinese, and Simplified Chinese environments. The corrupted value can affect collections that use System OU Name in query rules.
  • Delta Active Directory Group Discovery can skip membership changes for a group scope in a child organizational unit when another group scope is configured in a parent organizational unit. Collections based on the affected group membership might not update until a full discovery runs.

Software updates

  • After you manually renew the WSUS signing certificate for third-party software updates, the console can continue to display the certificate's previous start and expiration dates.
  • Configuration Manager-managed Windows Update policies can remain on clients after you set Enable software updates on clients to No in client settings. Clients can continue to use WSUS instead of receiving updates through Intune.
  • WSUS maintenance can fail when the software update point and WSUS are on the site server and the WSUS database uses Windows Internal Database (WID). Affected maintenance operations include adding indexes and removing obsolete updates.
  • A Windows feature update deployed through Configuration Manager can roll back to the previous version of Windows after the device restarts.

Operating system deployment

  • A required task sequence deployed with Only media and PXE (hidden) can be unavailable during PXE or boot media startup even when the SMSTSPreferredAdvertID machine or collection variable specifies its deployment ID. The device reports that no task sequences are available.
  • Task sequence policy retrieval through a cloud management gateway can fail in Windows PE when the boot media uses a CNG v3 certificate with a Key Storage Provider (KSP).
  • An operating system deployment task sequence can fail in Windows PE when the client relies on boundary group relationships to locate a management point instead of having one directly assigned to its boundary group. The failure can report a misleading certificate error.
  • Application content downloads through a cloud management gateway can fail during an operating system deployment task sequence when an older revision of the application contains a deleted deployment type.
  • Configuration Manager can incorrectly report that a boot image update succeeded when a Windows PE optional component or language pack fails to install. The resulting incomplete boot image can cause an operating system deployment to fail or a device to restart unexpectedly.
  • Duplicate records for the same Microsoft Entra-authenticated device can appear in the Configuration Manager console after an operating system deployment.
  • During operating system deployment in Windows PE, a device can switch to a management point outside its boundary group after requesting its client identity.

Migration

  • Microsoft 365 Apps updates can be missing from a migrated software update deployment package even though the migration job reports completion.

Configuration Manager console

  • Editing filter criteria and pressing Enter in Resource Explorer or other console lists can clear the filter or return incorrect results instead of applying the updated criteria.
  • The Configuration Manager console can unexpectedly close when you open the Windows Servicing dashboard immediately after starting the console.
  • Selecting Status Messaging Operational success or failure in the Client Health Dashboard can display the same device list for both results, with incorrect device counts.
  • When you import a Cryptography API: Next Generation (CNG) certificate for a distribution point from a Configuration Manager console that isn't running with elevated permissions, the certificate can be imported as a legacy Cryptographic Service Provider (CSP) certificate instead.
  • The Speed property for Network Adapter in Resource Explorer can appear empty even though hardware inventory collected the value.
  • The Configuration Manager console can crash when you delete a collection or view Cloud Attach settings if the Cloud Attach configuration has no associated Microsoft Entra web application. Related collection and cloud-management PowerShell operations can also fail.
  • The Configuration Manager console accepts imported self-signed certificates when configuring a distribution point for HTTPS. These certificates are now rejected during validation.
  • The Operating System Deployment group in Management Insights can show Action needed even when no insights appear in the list.

Tools and remote control

  • Configuration Manager Service Manager, Policy Spy, and Client Spy can fail to connect to remote computers when NTLM authentication is disabled.
  • Remote Control Viewer can fail to record session status messages when NTLM authentication is disabled or the user belongs to the Protected Users security group.

PowerShell

  • The New-CMFolder cmdlet fails to create a folder under Scripts when you specify .\Scripts for ParentFolderPath, reporting that the folder path is invalid.

Hotfixes that are included in this update

  • KB 37426535: Summary of changes in Configuration Manager current branch, version 2603
  • KB 33247081: Connected Cache update for Microsoft Configuration Manager versions 2409, 2503, 2509 and 2603
  • KB 37942646: Cloud management gateway virtual machine scale set image update for Microsoft Configuration Manager
  • KB 38232642: Security update for Microsoft Configuration Manager Console Extension
  • KB 38982839: Security update for the SMS Provider and administration service
  • KB 39398030: Security update for scripts, the SMS Provider, the Message Processing Engine, and Discovery Data Record processing