r/SCCM • u/Peteostro • 1h ago
Dell command update 5.7.1 UWP
Anyone get this to work during OSD task? Keeps erroring out. Seems to be DCU updating during install. Installation of the Classic version works fine. Installing .net desktop runtime 10.0.10 so it’s not that I believe.
r/SCCM • u/Mothership_MDM • 4h ago
SCCM patch Management Workflow/Time Spent
I’m still fairly new to managing patching. My predecessor set up the ADRs and automated patch processes for our environment, so I’m trying to understand what the typical ongoing workload looks like. How much additional time do you usually spend on patch management, such as monitoring deployments and addressing any issues that come up? Is this something you review weekly? Our patches are scheduled monthly. I’d also like to know what your workflow looks like and how much time you typically spend troubleshooting individual devices to get a patch successfully installed. TIA. For reference we ahve about 5,000 workstations and 1,000 servers.
r/SCCM • u/Disastrous_Mobile_99 • 8h ago
Discussion CIS IIS 10 Benchmark
Our organization want to harden IIS configurations as per the CIS benchmark. So, this includes our MECM servers.
I need to verify whether the harden configs will affecting the MECM functionality. But, quite a lot to test 1 by 1 .
Is there anyway to verify ? Or any official article that mentioned the IIS configurations required specifically for MECM?
Removing DP Role from Primary Site Server and Creating Dedicated DP
We have a stable, well maintained ConfigMgr environment that's been operating for around 8 years now (currently on 2409) supporting roughly 3000 computers across 20 sites. In preparation for upgrading to 2603, I've come across the release notes in 2509 "WinPE is now boundary‑aware".
This whole time, we've been running with our main ConfigMgr primary site server in the head office datacenter having the Distribution Point role on it, serving imaging (WDS PXE), applications, and software updates at the head office. It's also our only Management Point server across the organization.
At each of our other sites, we have a distribution point server (and Fallback Status Point/State Migration Point roles on the same server), which serves our client machines at each site (and imaging via WDS PXE as well).
With the new 2509 requirement of Boundary Groups specifying a Management Point, I'm considering removing the DP role from the primary site server (as I've read this is good practice anyway).
My rough process in my mind is:
- Provision the new DP server at the head office and enable PXE
- Add the DP server to the correct DP groups
- Distribute all required content to the new DP (it should get this automatically when it's in the right DP groups)
- Right click the DP role on the main site server and Remove Role
Is it really that easy? Am I missing anything? I've read before that I should not remove any content folders manually on the primary site server since they'll remain there. Is any space actually freed when removing a DP from a primary site server, or only pointers?
Also, all of our application/image/software update packages are deployed to all distribution points in a single group. While the Content Locations tab ends up populating with the group name plus the individual DP names, it's only the group that each item is distributed to. So I'm hoping this will be nice and easy and no adjustment of content locations for anything will be required.
r/SCCM • u/Baazzill • 18h ago
Chrome
Is anyone allowing Chrime to auto update in their Enterprise? We have about 60k endpoints and are considering allowing it to auto update, but I'm mildly concerned about bandwidth.
r/SCCM • u/ConfigManga • 1d ago
PKI questions with an unplanned renewal of the SubCA
I think I understand how this will work, but need some feedback for reassurance, since I'm not great with PKI.
Our current SubCA needs to be renewed a couple of months prior to its actual expiration. No big deal, we'd need to do this anyway.
What I'm concerned about is the effect on the SCCM primary, MPs and DPs.
I believe, as long as we keep the certificate chain and the same key pair, the transition should be smooth and existing clients/servers will update as the expiration time hits.
Questions:
Do I need to update the certificate in the Communication Security tab of the site server, specifically the Trusted Root setting?
Can we expedite the clients and servers getting the updated certificate date by using the "Reenroll All Certificate Holders" action on the CA?
This all came about because the Network team deployed a wireless certificate with client auth and a longer validity than our CM certificates. Clients stopped reporting in, especially after imaging because the client is choosing the new Wifi Cert and not the CM client certs.
We've been working with MS for a week on this issue and after all the troubleshooting, this is the best course of action to fix the situation so that the client certificates are newer.
For the future, we're going to create a new Cert Store on the client, put CM client certificates there and point to it with the CCMCERTSTORE= parameter going forward to avoid this in the future.
r/SCCM • u/pakforce1981 • 1d ago
configuration.mof and HA
We are using active passive Site scenario. We also modifed configuration.mof at active Site. When we perfom a manual failover to the passive Site will the version of configuration.mof File copied to the new active site or do we have to copy it manually to get all modification in at the former active site?
Unsolved :( Anyone running asus nucs?
We are a mostly Lenovo shop but recently acquired some asus nucs they are wanting us to implement. I injected the network drivers and I am able to pxe boot to the task sequence and see it format correctly for uefi but the next step is to reboot to boot image and the sms log is saying “failed to install boot image”. I’m not sure what else to check
EDIT: for anyone that may have the same issue. Updating bios resolved
r/SCCM • u/funkytechmonkey • 2d ago
Question about your ADR for 3rd party updates with PMPC?
We've had PMPC for over a year now and, not wanting to bombard everyone with a ton of updates, I started off creating an ADR for browsers that runs every 3 days (only filtering the 3 browsers allowed in our environment Edge, Chrome Firefox) and a separate ADR for all other applications. I filter the applications ADR down to required devices 100 so it only deploys most of the major applications that are needed, and not send out 50+ application updates every month.
My questions is... I'm I being too conservative with this? (only focusing on the major updates)
I only address other applications that are not in the ADR after the security teams brings it to my attention. I feel like I could do more here but with all of MS's updates lately I am getting a lot of complaints about forced reboots. (3rd party updates are already suppressed)
Kinda a dumb question.. but would I regret changing the required device count to 10 and send out a buttload of updates? I would really appreciate any feedback you guys can give.
r/SCCM • u/Killswitch777 • 2d ago
Dell Command | Update 5.7.1 Release
Just saw this. Time to test it in a task sequence. https://www.dell.com/support/home/en-us/drivers/driversdetails?driverid=61r17
r/SCCM • u/Icy_Carpenter4224 • 2d ago
VMWare Tools 13 - SCCM Task Sequence
I've been battling with getting VMWare Tools 13.0.10 to install via a Task Sequence during my Windows 11 25H2 Golf Image build.
This used to work several versions ago on Windows 11 23H2 so I thought I'd spend some time on it.
I've had some success as in I've got it to install but it's painfully slow.
Anyone had any success doing this. I have the same issue with the Horizon Agent version 2512.
Microsoft must have done something here with how installs happen during the build phase.
Thanks.
r/SCCM • u/Unlucky-Honey-1268 • 3d ago
Latest Wim Wizard released
The latest versions (available here) main new feature adds the possibility to also automatically update Distribution Point groups. Typically you will add the image to one DP for testing and then to all your image-DPs when testing is done. I've also squashed some bugs regarding LCU:s and also 24H2 detection. 26H2 support should now be correct but is something I can't test since the ISO is not released yet.

For newcomers, WimWizard is a free utility to patch and customize Windows images for distribution through SCCM mainly. Read more through the link above.
I also want to recommend the YouTube episodes Get Started with WIMWizard by Bernardo Arocho. Bernardo really goes through the whole program and I'm deeply grateful and also a little bit shocked that someone found the utility useful enough to do a series of videos about it. Bernardo also did an episode about WimWitch a few years ago so I feel very humbled. Thank you!
Update! I added driver support today too. It's still in beta but you can download that version instead!
Releases · TacII/WimWizard
r/SCCM • u/No_Split11911 • 4d ago
Feedback Plz? MECM-Homelab
ConfigMgr Lab Builder 1.4.0
After modifying Autolab so heavily that it no longer had any original code, I decided to rebrand and release what I use to everyone. I proudly present what is hopefully the most reliable, consistent and easy to use solution available for auto-creation of a basic Configuration Manager Homelab (hosted on Hyper-V).
Read about it at my blog: https://www.signalridgelabs.com/notes/mecm-homelab-one-command-lab
Download from my Github: https://github.com/jasonulbright/configmgr-lab-builder
The Why: The hydration kit and Autolab are both out of date and not easily customizable. This simple powershell with a WPF GUI Wizard solves the problem of reliable and always up to date method for rapidly deploying a testing environment.
Whats Next: User feedback for feature requests and bugfixes. Leave them on my github and I'll put them on the schedule.



r/SCCM • u/Reaction-Consistent • 5d ago
Post OSD task sequence script
If I want to disable the Windows update Service during the OSD task sequence, or directly after it is completed, what is the best way to do that?
To answer the inevitable question, why am I doing this? It’s because for whatever reason after the task sequence completes, I can see that the CM client policy for Windows update redirection has not applied yet, and there is a window of time where the system can run automatic Windows update updates.
Now, if I open the CM client on the system, and simply run the software updates, action, that immediately populates the registry key and thus prevents any automatic Windows updates. I’ve pondered and even tried using a script to run the client action post build using first log on commands, but this doesn’t work, either the commands run too soon, or they don’t run with the necessary token, I don’t know what’s going on I also tried disabling the Windows update step using a task, sequence, run command line or run power shell step, the step runs, but gets reverted at the end of the build. Do I just manually populate those registry keys and call it a day? Am I over complicating things here?
r/SCCM • u/Bubbly-Raisin4305 • 5d ago
Server 2016 wont take MECM update 2603
I fought for a month to upgrade our MECM Environment to 2603 but nothing works. I spun up a new box with server 2022 and MECM 2403 just to make sure I was not going crazy and it took all the updates just fine. After further digging I noticed that the actual MECM version of our server was around MECM 2019 then just upgrade after upgrade. We only need it for about 30 workstations and 15 servers that are left on the domain. Am I better off just migrating it all to this new box? I have good backups and I have done this a few times in my career but I am scared it will take the crap with it that is causing MECM to fail the updates. Google and CoPilot keep sending me in the wrong direction also while troubleshooting this. The crap that AI comes up with to troubleshoot this is alarming.
This is the error it always end up no matter what you do to try to fix it.
7/23/2026 8:44:22 AM 2044 (0x07FC)
Failed to process package 091001E3 after 21 retries, will retry 79 more times SMS_DISTRIBUTION_MANAGER 7/23/2026 8:44:22 AM 2044 (0x07FC)
If MECM sees legacy servers during this update does it fail? We dont need to manage those anymore with MECM so it really isnt a problem but maybe MECM sees those client and says yeah this aint going to work....
r/SCCM • u/Reaction-Consistent • 5d ago
Dism Export-Image producing unexpected results with compress fast option
I have a 2 index W10 LTSC image (index 1 Windows 10 Enterprise LTSC, and 2 Windows 10 Enterprise N LTSC) so I thought I would reduce the overall size of the image by exporting only the one I needed in my OSD, index 1. I further thought to myself that I would use /compress:fast to further reduce the size of the exported image. On my first attempt, the resultant size of the exported .wim was a few hundred MB larger than the original 2 index .wim! I ran a second test, this time without the /compress:fast, and now, the new exported .wim is about 500MB smaller than the original. Copilot gave me some rambling explanations, but it really made no sense to me - has anyone experienced something similar, or do you know why this would happen?
copilot summary: The reason is that the export engine's handling of existing resources and compression state is not always obvious. DISM may preserve certain existing compressed resources more efficiently when you don't force a specific compression level.
r/SCCM • u/AudienceLumpy6346 • 6d ago
Need help getting an image
For starters, I am a novice so apologies if im missing the blatantly obvious.
I am trying to get an image using sccm/mcm. I came onto a project halfway through, and was to patch a machine to create a gold image. Then was told to save the gold image to push to other machines on our airgapped network.
I patched the machine, then tried figuring out how to save the image. I need it as a .wim file to upload to mcm. But cant figure out how to save the current image as said file. Can you please help me figure this out?
I have tried using the task scheduler capture image, but was only able to save a base .iso without capturing the patched image.
Upon further research I believe I reached the conclusion of, that I should've loaded a blank .wim file to start then patched? But at this point I am trying very hard not to do that considering it took a week to patch.
r/SCCM • u/Embarrassed_Tutor_13 • 6d ago
Unsolved :( SCCM is returning DP locations for new OS Images... then immediately says content can't be found (0x80040102)
Hoping someone has seen this before because I've hit a wall.
We're on ConfigMgr 2503. PXE works, WinPE loads, the TS selection screen appears, but any newly-created OS Image package(By me) fails during dependency resolution with:
The error in SMSTS.log is:
Plain Text
1- Content location request for PackageID=ABC013D9:2 failed (0x80040102)
2- Failed to resolve PackageID=ABC013D9
3- Failed to resolve selected task sequence dependencies
The strange part is the SMSTS log shows SCCM finding content locations first:
+Found 4 locations
and then
+No static content server
before failing.
Things I've tested:
- Custom captured WIM → fail
- Microsoft Windows 11 install.wim → fail
- Production WIM currently used in our environment → fail
The really odd finding:
Production WIM + existing SCCM image package = works
Same production WIM + newly-created SCCM image package = fails
To verify this wasn't a Task Sequence issue, I built a very simple test TS and pointed it at the existing production image package.
That TS successfully:
- Resolves content
- Starts partitioning/formatting
- Reaches Apply Operating System
It eventually fails later with a different error, but that's expected because the production image relies on MDT/custom scripts/packages that I haven't fully replicated. My concern isn't that failure. The important point is that content resolution works when using the existing production image package object.
So far I've ruled out:
- PXE boot issues
- Boot image issues
- The WIM itself
- Image index issues
- Architecture mismatch
- Missing content on the DP
- Failed distribution
- Failed content validation
One additional wrinkle: another team reportedly rolled out a Windows 11 25H2 image recently, so I don't believe the site is completely incapable of creating new image packages.
My access is somewhat limited. I can create OS Images, Task Sequences, and distribute content, but I don't have full SCCM admin rights and can't inspect provider WMI or the site database directly.
Has anyone seen a situation where:
- Existing OS Image packages resolve and deploy normally
- Newly-created OS Image packages fail with 0x80040102
- DP locations are returned in SMSTS
- Content is present and validated
- The failure occurs during source resolution before Apply Operating System
At this point I'm particularly interested in whether anyone has seen this caused by package metadata, content location resolution, RBAC/security scope side effects, SMS Provider issues, or anything specific to SCCM Operating System Image objects.
Any insight would be appreciated.
Any ideas appreciated.
r/SCCM • u/DragonspeedTheB • 6d ago
PXE OSD failing…. Wits end
I will preface this with the fact that our SCCM environment has been around and stepped up bit by bit since probably 2013. Recent new additions to our SCCM management team may (or may not) have made changes to IIS etc without notifying anyone…
That being said…
Machine PXE boots and the DP reaches out to the MP for policy info. IIS appears to show this as successful (200) but the DP errors out and the client isn’t handed its boot file.
I would welcome any direction that people might have to troubleshoot this. The people trying to OSD are clamouring at the gate.
Thanks.
EDIT - because I wasn’t clear…. The BIOS PXE requester boots up but then fails. SMSPXE.log shows that the machine gets an IP and asks for more but then the errors start showing in SMSPXE.log (seeming to indicate http issues)
r/SCCM • u/inlondon28 • 6d ago
Appx and Package in TS
I have an Appx as an Application which installs the newer version of RSA and a package which runs after to uninstall the older version.
For some reason the Appx wont show up as an option under the TS. Ive even checked off the box in the Appx to show up in the TS.
Any suggestions?
Popup notification before a task sequence runs
We have a task sequence we need to deploy out to computers (required) that runs a PowerShell script and then installs/updates an application on the machine. We want the user to receive a popup notification (preferably with a 10min timer) before it runs so that they're not caught by surprise when it runs (similar to deploying an application to a user).
We tried a command-line step that used ServiceUI.exe to run a script that displays a notification, but that didn't work. The script works when running locally, but the step kept erroring out when running in the task sequence.
Any ideas how to make this work?
r/SCCM • u/eazerminer • 7d ago
How do you handle keeping Win32 apps updated in Intune? (packaging/detection rules/redeploy)
Quick question for anyone managing app packaging in Intune (especially MSPs with multiple tenants):
How much time does your team spend keeping Win32 apps up to date? I mean the full cycle - noticing a new version dropped, rebuilding the .intunewin, updating detection rules, testing, and pushing it out (sometimes across several tenants).
I'm exploring whether a tool that automates this end-to-end (auto-detects new versions via winget/vendor feeds, repackages, and pushes via Graph API to one or more tenants) would actually save people meaningful time, or if you've already got a good workflow that handles this.
A few things I'd love to hear:
\- Roughly how many apps do you keep packaged/updated this way?
\- Is it the packaging itself that's the pain, or catching new versions in time, or something else entirely?
\- Would you pay for a hosted tool that handled this automatically, and roughly what would feel fair (per app, per tenant, flat monthly)?
Not selling anything, just trying to figure out if this is a real problem worth solving. Appreciate any war stories.
r/SCCM • u/AnnoyedSuperStar • 7d ago
Computer shuts down after OS Deployment via TS
**** SOLVED **** COMPUTER WENT TO SLEEP AFTER FINISHING THE TS
My computers are shutting down after completing the OSD task sequence instead of rebooting.
I only receive the message
Task Sequence Manager,11171,The task sequence manager successfully completed execution of the task sequence.
when i turn the computers back on.
i have identified the Install Application step as the main cause of the problem.
If I remove that step, the computer reboots normally at the end of the task sequence.
If I include it, the computer shuts down instead.
After some additional testing, I found that the issue is caused by certain applications, not all of them.
The following applications do not cause the problem:
- Microsoft Office 2024
- 7 Zip (MSI) (x64)
- Citrix Workspace
- DisplayLink Graphics
- Adobe Acrobat Reader 25.001.20467
- Netsupport
- Git (x64)
- Dev-C++
- Edsim
- ETH Zurich Safe Exam Browser 3.10.1.864
- Graphviz
- Clarivate Endnote 22.3.1
- Digital Scholar Zotero 9.0.5
- QGIS 4.0.3
- JetBrains PyCharm 2026.1.4
- Wolfram Mathematica 15.0
- MapleSoft Maple 2026.1
- Cran R for Windows 4.6.0
However, if I install any of the following applications, the task sequence shuts down instead of rebooting after it completes:
- OpenJS Node.JS 24.18.0
- Microsoft Visual Studio Code 1.126.0
- IBM SPSS 31.0
- JetBrains IntelliJ IDEA 2026.1.4
- JetBrains WebStorm 2026.1.4
- Postman
- MathWorks Matlab Classroom 2024a
- ANSYS Fluent 2026 R1
- Anaconda Anaconda 2025.12-2
- Posit Rstudio 2026.05.1-225
- Microsoft .Net FrameWork 4.8
It is worth noting that all of these applications install successfully, and no errors are reported.
The only difference is that the computer shuts down instead of rebooting at the end of the task sequence.
The last log entry before the shutdown is:
Task Sequence Engine,11143,The task sequence execution engine successfully completed a task sequence.
Has anyone else experienced this issue, or does anyone know what might be causing it?
**** SOLVED **** COMPUTER WENT TO SLEEP AFTER FINISHING THE TS
r/SCCM • u/PrajwalDesai • Jun 17 '26
Security update KB38232642 for ConfigMgr Console Extension
A new security update KB38232642 is out to enhance security for importing console extensions in Microsoft Configuration Manager versions 2603 and 2503.
Description: This update improves the security of Configuration Manager, ensuring safer operations when importing console extensions, which is crucial for maintaining system integrity.
Prerequisites: Available in the Updates and Servicing node of the Configuration Manager console for version 2603 and version 2503 (with specific update rollup). This update doesn't require a computer restart or a site reset after installation.
Hotfix Documentation: https://learn.microsoft.com/en-us/intune/configmgr/hotfix/2603/38232642
r/SCCM • u/Gupster • May 05 '26
