Wednesday, September 14, 2016

Restore SCCM Report

Recently I had lot of questions how to restore the SCCM reports which are accidently deleted by SCCM users.

first option comes in my mind that is simply restore the DB will work, but again I have thought and the following trick works.

Navigate to registry - HKEY_Local_Machine\Software\Microsoft\SMS\SRSRP\ change the SRSInitializeState  key to 0 and monitor the srsrp.log file. It will re-import the standard reports along with the custom security settings.

and now issue is gone and all the default reports are appeared again in SCCM.

Tuesday, September 13, 2016

Configuration Manager and Windows ADK for Windows 10, version 1607

If you are using Configuration Manager and you are planning to deploy Windows 10, version 1607, This page explains the support matrix for Configuration Manager versions and Windows 10 versions. 
The Windows Assessment and Deployment Kit (ADK) for Windows 10, version 1607, is available on the Microsoft Hardware Dev Center (adksetup.exe file version 10.1.14393.0).
The newer ADK is only needed if deploying Windows 10, version 1607
MS have limited support for Windows 10, version 1607, in Configuration Manager version 1602. Users who are still on this version of Configuration Manager and will be deploying the newer version of Windows 10 can upgrade the ADK to the latest version if desired, or remain with the prior version, Windows ADK for Windows 10, version 1511. Beyond that, MS do not support deployment of Windows 10, version 1607, with older versions of Configuration Manager. So the need for this new version of the Windows ADK does not apply.
Windows 10 ADK Version
ConfigMgr Version150715111607
1511SupportedSupported
1602SupportedSupported 1Supported 2
1606Supported 1Supported


1 The Windows ADK for Windows 10, version 1511, provides basic forward compatibility and can be used for image capture, image apply, driver injection, and offline update servicing of Windows 10, version 1607, if absolutely necessary. We strongly recommend upgrading to the latest ADK version, but basic forward compatibility is supported during the transition period.
2  The newer ADK is only needed if deploying Windows 10, version 1607.








Sunday, September 11, 2016

Microsoft Intune provides support for iOS 10

Earlier Apple announced the availability of iOS 10 (with public release scheduled for 9/13/2016). Since the initial beta bits were first released, Microsoft have been busy working to ensure that all existing MDM and MAM scenarios are compatible with the latest version of iOS and Mirosoft has announced that Microsoft Intune will support iOS 10. All existing Intune features currently available for managing iOS devices will continue to work seamlessly as users upgrade their devices and apps to iOS 10. In addition, iOS 10 will also work with customers managing in hybrid with both Intune and Configuration Manager.

Wednesday, August 17, 2016

Goodbye Patch Tuesday

Patch Tuesday is soon to be a thing of the past. Beginning in October, Microsoft will deploy fixes for Windows 7, Windows 8.1, Windows Server 2008 and Windows Server 2012 with a single cumulative monthly patch. This is designed help reduce fragmentation across your company’s PCs. The new system is right in the line with how updates are currently deployed for Windows 10.
From October 2016 onwards, Windows will release a single Monthly Rollup that addresses both security issues and reliability issues in a single update. The Monthly Rollup will be published to Windows Update (WU), WSUS, SCCM, and the Microsoft Update Catalog. Each month’s rollup will supersede the previous month’s rollup, so there will always be only one update required for your Windows PCs to get current. i.e. a Monthly Rollup in October 2016 will include all updates for October, while November 2016 will include October and November updates, and so on. Devices that have this rollup installed from Windows Update or WSUS will utilize express packages, keeping the monthly download size small.
Windows will proactively add patches to the Monthly Rollup that have been released in the past. Microsoft's goal is eventually to include all of the patches we have shipped in the past since the last baseline, so that the Monthly Rollup becomes fully cumulative and you need only to install the latest single rollup to be up to date. We encourage you to move to the Monthly Rollup model to improve reliability and quality of updating all versions of Windows.Microsoft is planning to add these previously shipped patches over the next year and will document each addition so IT admins know which KBs have been included each month.
It’s a big departure from the current system, under which Microsoft sporadically releases individual patches for the older platforms. That has some advantages, allowing IT administrators to selectively deploy updates as needed, but it also comes with some serious drawbacks. Under the current system, individual PCs frequently wind up with different updates installed, which causes syncing problems, boosts scan times, and ups testing complexity. Even just pinpointing the right patches before applying them can be a pain.
Here’s how the new system will work. In October, up-to-date PCs running the older platforms will receive just a single package of security and stability fixes from Windows Update, Windows Server Update Services (WSUS), System Center Configurations Manager (SCCM) and the Microsoft Update Catalog. If you delay the update in October, you’ll be prompted to install it again in November, along with another single set of patches for that month, and so on. Each month’s update will include patches for all previously-uninstalled months, from October onwards.
older updates will begin to be included in the monthly patch rollouts, dating all the way back to Service Pack 1 for Windows 7. That means that — at some point — you’ll be able to get fully up to date with just a single installation, no matter the current state of your PC.
Microsoft is allowing one exception for its new all-in-one update system, affording the ability to download and deploy security patches separately from stability fixes. That will reduce the size of the initial update needed to secure your company’s PCs as quickly as possible. Those updates will be available from WSUS, SCCM and the Microsoft Update Catalog, not Windows Update.
Servicing Stack and Adobe Flash updates won’t be included in the rollups. Microsoft will move to the same monthly rollup model for the .NET Framework in October too.
for more about patch Tuesday see on Patch Tuesday

Tuesday, August 2, 2016

SCCM 1606 New features

If you’ve been installing SCCM Technical Preview in your lab, SCCM 1606 contain most features included in the latest technical previews.
Consult technical Articles for a full features list. 1606 also applies the latest KB/fixes to fix known bugs…. Including KB3155482 but not KB3174008 (which was release a week prior to 1606). If you had already installed KB3174008, 1606 will revert the fixes included in KB3174008. Microsoft recommendation is to skip this KB (unless you are really blocked by this), update to 1606 and wait for a new KB that will be available for 1606 soon. (Which will include KB3174008).
Here’s our list of favorite features
  • Option for clients to switch to a new software update point
    • You can enable the option for Configuration Manager clients to switch to a new software update point when there are issues with the active software update point.
  • Per-app VPN for Windows 10 devices
    • For Windows 10 devices managed using Configuration Manager with Intune, you can add a list of apps that automatically open a VPN connection that you have configured through the Configuration Manager admin console. You have the option of restricting VPN traffic to those apps, or you can continue to allow all traffic through the VPN connection.
  • Customize the RamDisk TFTP block size and window size on PXE-enabled distribution points
    • You can customize the RamDisk TFTP block size and window size for PXE-enabled distribution points. If you have customized your network, it could cause the boot image download to fail with a time-out error because the block or window size is too large. The RamDisk TFTP block size and window size customization allow you to optimize TFTP traffic when using PXE to meet your specific network requirements
  • Improvements to the Install software updates task sequence
    • A new task sequence variable, SMSTSSoftwareUpdateScanTimeout, is available to give you the ability to control the timeout on the software updates scan during the Install software updates task sequence step. The default value is 30 minutes.
    • There have been improvements to logging. The smsts.log log file will contain new log entries that reference other log files that will help you to troubleshoot issues during the software updates installation process.

Tuesday, June 28, 2016

Cireson ConfigMgr User Device Affinity app

The User Device Affinity app enables administrators, help desk staff, and other users to easily search, view, edit, and manage user to device relationships outside of the Configuration Manager Console.

With the User Device Affinity app, you can easily:

  1. View existing user to device relationships
  2. Associate new users to existing devices
  3. Remove users from existing devices
  4. Add new devices to existing users
  5. Remove devices from existing users
  6. Search and filter users and devices for management of UDA relationships
  7. Launch Remote Manage in the context of a computer

Associating users to their primary devices (user device affinity) is a great feature of Configuration Manager. It allows you to easily deploy applications to a user’s primary device (often referred to as ‘user centric software delivery’). It also provides helpful information to your Help Desk so when a user calls in for support, they can have information on what computer they might be using. The problem with user device affinity is getting it configured, and configured correctly, in your environment. There are over a half dozen ways to associate users to computers – some automated, however most manual – which can lead to mistakes. The Cireson User Device Affinity app easily allows an administrator to view and manage the relationships between users and devices. This process is completed outside the Configuration Manager Console, which reduces complexity and confusion.

Thanks to Cireson, who made this fantastic tool.

for more detail and download the tool visit on cireson 

credit goes to Cireson. 

Thursday, March 24, 2016

Current Branch Update ConfigMgr 1602

Microsoft announced the release today of System Center Configuration Manager (SCCM) 1602, which is the latest update to its device management product. The "1602" part of the update's name refers to its year and month release time (as in "2016 February"), but Microsoft announced its arrival today in March. It's just an update and not a new current branch for business release.
The current branch of System Center Configuration Manager was released on December 8, 2015. Today's announcement was the first update for the current branch with new features, not a brand new release.
SCCM as a Service
Microsoft now updates SCCM like the service model of Windows 10, with updates pushed down at certain intervals, called "current branch" and "current branch for business" for summer and fall releases. There's also a "long-term servicing branch" option for Windows 10. Possibly, Windows 10 will get an altered update cycle with this year's releases
Prior to this update, the current branch release of SCCM was known as "1511" (for "2015 November"). Microsoft announced the SCCM 1511 current branch in December.
A new current branch update is supposed to appear every month, per past Microsoft descriptions of its update process. A new current branch for business update is expected to appear every four months, so 1602, released after three months, wasn't the next current branch for business release.
These updates appear in the Updates and Servicing node of SCCM's console.
Microsoft has a similar update model for Office 365, but it uses slightly different terminology. "Branches" are called "channels" for Office 365 updates. Office 365 has "current channel" updates every month and "deferred channel" updates every four months.
If we fail to update to the next current branch for business after eight months' time, then we risk running "unsupported software." That means that the software will no longer get updates and security patches, a risky situation.
SCCM 1602 Perks
Organizations are getting plenty of perks with SCCM 1602. It enables in-place upgrades of Windows Server 2008 R2 to Windows Server 2012 R2.Other benefits include the ability to see the clients that are online and view the "health" of Windows 10 devices.
Another big benefit of SCCM 1602 concerns the management of Office 365 clients. They can be managed using SCCM's "Software Update Management workflow." This capability is possible for "Office 365 ProPlus, Visio Pro for Office 365 and Project Pro for Office 365,"
Intune-SCCM Management
Microsoft also announced new capabilities with SCCM 1602 when integrated with Microsoft Intune, which is Microsoft's mobile device management service. Organizations can use Intune as a standalone tool or it can be integrated with SCCM. The standalone tool tends to get its new capabilities faster than the integrated SCCM solution.
One new capability in the integrated Intune-SCCM solution is the ability to impose conditional access on devices. we can now specify with SCCM 1602 that devices have to have current software updates, antimalware protection and BitLocker encryption to connect with a network.
SCCM 1602 with Intune also permits Microsoft Edge browser deployments to devices. Edge browser settings can be changed with the SCCM 1602-Intune combo.
Some management capabilities for Apple iOS devices are unlocked with SCCM 1602 and Intune. we can set policies to "dynamically change settings such as server name or port for iOS applications."  They can enable iOS Activation Lock on devices or they can bypass it.
This update includes the following improvements:
  • Client Online Status: You can now view the online status of devices in Assets and Compliance. New icons indicate the status of a device as online or offline.
  • Support for SQL Server AlwaysOn Availability Groups: Configuration Manager now supports using SQL Server AlwaysOn Availability Groups to host the site database.
  • Windows 10 Device Health Attestation Reporting: You can now view the status of Windows 10 Device Health Attestation in the Configuration Manager console to ensure that the client computers have a trustworthy BIOS, TPM, and boot software.
  • Office 365 Update Management: You can now natively manage Office 365 desktop client updates using the Configuration Manager Software Update Management (SUM) workflow. You can manage Office 365 desktop client updates just like you manage any other Microsoft Update.
  • New Antimalware Policy Settings: New antimalware settings that can now be configured include protection against potentially unwanted applications, user control of automatic sample submission, and scanning of network drives during a full scan.
  • Windows 10 Servicing: New improvements were added based on your feedback such as filters in servicing plans for upgrades that meet specified criteria, integration with deployment verification and a dialog in Software Center when starting an upgrade.
This update also includes new features for customers using System Center Configuration Manager integrated with Microsoft Intune. Some of the features that you can expect to see are:
  • Conditional Access for PCs Managed by Configuration Manager: You can now use conditional access capabilities to help secure access to Office 365 and other services on PCs managed with Configuration Manager agent. Conditions that can be used to control access include: Workplace Join, BitLocker, Antimalware, and Software Updates.
  • Windows 10 Conditional Access Enhancements: For Windows 10 devices that are managed through the Intune MDM channel, you can now set and deploy an updated Compliance Policy that includes additional compliance checks and integration with Health Attestation Service.
  • Microsoft Edge Configuration Settings: You can now set and deploy Microsoft Edge settings on Windows 10 devices.
  • Windows 10 Team Support: You can now set and deploy Windows 10 Team configuration settings.
  • Apple Volume Purchase Program (VPP) Support: You can now manage and deploy applications purchased through the Apple Volume Purchase Program for Business portal.
  • iOS App Configuration: You can now create and deploy iOS app configuration policies to dynamically change settings such as server name or port for iOS applications that support these configurations.
  • iOS Activation Lock Management: New capabilities include enabling iOS Activation Lock management, querying for the status, retrieving bypass codes, and performing an Activation Lock bypass on corporate-owned iOS devices.
  • Kiosk Mode for Samsung KNOX Devices: Kiosk mode allows you to lock a managed mobile device to only allow certain apps and features.
  • User Acceptance of Terms and Conditions: You can now see which users have or have not accepted the deployed terms and conditions.

.

PXE Issue after SCCM CB 1806 upgrade

Recently i had upgraded my SCCM environment 1806 and after upgrade suddenly all PXE servers stopped working. While initiating the PXE ...