Eswar Koneti's Blog

All about Configmgr and its connected objects…….

  • About Author
      View eswar koneti's LinkedIn profile
  • Enter your email address to subscribe to this blog and receive notifications of new posts by email.

    Join 106 other subscribers

  • Awards


  • FaceBook Updates

  • Catagories

  • Meta

  • Copyright!

    All the blog posts in this website are owned by Eswar Koneti and may not be reused in any mode without prior approval of Eswar Koneti. You may quote one paragraph from the blog posts if you link to the original blog post.
    Happy Reading!

ConfigMgr (SCCM) 2012 site Maintenance Tasks

Posted by Eswar Koneti on 23rd January 2012

What are the site maintenance task and where are they in ConfigMgr 2012 and how do I configure them ?

System Center 2012 Configuration Manager sites and hierarchies require regular maintenance and monitoring to provide services effectively and continuously. Regular maintenance ensures that the hardware, software, and the Configuration Manager database continue to function properly and efficiently.

Each Configuration Manager site supports maintenance tasks that help to maintain the operational efficiency of the Configuration Manager database. Several maintenance tasks are enabled by default at each site, and all tasks support independent schedules. Maintenance tasks are configured individually for each site and apply to the database at that site, however some tasks, such as Delete Aged Discovery Data, affect the information available at all sites in a hierarchy.

Site Maintenance Tasks in ConfigMgr 2012 RC2 :

From your administration node—>Site Configuration—>Sites.

image thumb2 thumb ConfigMgr (SCCM) 2012 site Maintenance Tasks

image thumb31 thumb ConfigMgr (SCCM) 2012 site Maintenance Tasks

 

TechNet Reference :http://technet.microsoft.com/en-us/library/gg712334.aspx

Additional Resources

Tags: , , , , , ,
Posted in SCCM 2007, SCCM 2012 | No Comments »

Installation of ConfigMgr(SCCM) 2012 RC2

Posted by Eswar Koneti on 22nd January 2012

After fixing SQL server Issue with the required patches , I have got installed configMgr 2012 RC2 on my lab after fixing the issue with SQL server 2008 R2 SP1 with CU4.

This Guide assumes that you have Domain Controller with DNS,DHCP(Optional) and Member server with server 2008 R2 Operating system.

Please go through the TechNet guide to more about configuration Manager 2012 http://technet.microsoft.com/en-us/library/gg682140.aspx
I will not go through the configuration of IIS,BITS etc which are needed as prerequisites for configmgr 2012 .for all these configurations,
please take a look at windows-noob.com for step by step http://www.windows-noob.com/forums/index.php?/topic/4045-sccm-2012-guides/
start the installation of SQL server 2008 R2 or SQL server 2008 on member server (which is ConfigMgr server) .

Supported versions of SQL Server 2008 for ConfigMgr 2012 RC2 are:

SQL Server 2008 SP2 Standard and Enterprise CU7
SQL Server 2008 R2 SP1 and CU4
SQL Server Express 2008 R2 and CU4
If you are running SQL 2008 SP2, install CU7 from http://support.microsoft.com/kb/2617148.
If you are running SQL Server 2008 R2 SP1, use CU4 from http://support.microsoft.com/kb/2633146.

You can use the command lines to install SQL server 2008 including SQL server 2008 R2 SP1 and cumulative update 4 from http://www.ronnipedersen.com/2012/01/installing-sql-server-2008-r2-for-configmgr-2012/ (The current supported configuration of SQL Server for System Center 2012 Configuration Manager, is Microsoft SQL Server 2008 R2 with Service Pack 1 and Cumulative Update 4.)

Once you are done with it ,start the installation of ConfigMgr 2012 RC2 from your downloaded media http://eskonr.com/2012/01/configmgr-2012-rc2-released/(http://care.dlservice.microsoft.com/dl/download/3/4/C/34C7656A-F89E-473C-8CE0-21DA5DB0717C/configmgr_2012_RC2_ENU_7703.exe)

clip image002 thumb1 Installation of ConfigMgr(SCCM) 2012 RC2

clip image004 thumb1 Installation of ConfigMgr(SCCM) 2012 RC2

clip image006 thumb1 Installation of ConfigMgr(SCCM) 2012 RC2

clip image008 thumb1 Installation of ConfigMgr(SCCM) 2012 RC2

clip image010 thumb1 Installation of ConfigMgr(SCCM) 2012 RC2

clip image012 thumb1 Installation of ConfigMgr(SCCM) 2012 RC2

The required prerequisites files are downloaded prior and placed in shared folder.

Download prerequisites files for ConfigMgr 2012 RC2 http://eskonr.com/2012/01/configuration-managerconfigmgr-2012-rc2-prerequisites-download/

clip image014 thumb1 Installation of ConfigMgr(SCCM) 2012 RC2

clip image016 thumb1 Installation of ConfigMgr(SCCM) 2012 RC2

clip image018 thumb1 Installation of ConfigMgr(SCCM) 2012 RC2

clip image020 thumb1 Installation of ConfigMgr(SCCM) 2012 RC2

clip image022 thumb1 Installation of ConfigMgr(SCCM) 2012 RC2

clip image024 thumb1 Installation of ConfigMgr(SCCM) 2012 RC2

image thumb10 Installation of ConfigMgr(SCCM) 2012 RC2

image thumb11 Installation of ConfigMgr(SCCM) 2012 RC2

image thumb12 Installation of ConfigMgr(SCCM) 2012 RC2

image thumb13 Installation of ConfigMgr(SCCM) 2012 RC2

image thumb14 Installation of ConfigMgr(SCCM) 2012 RC2

image thumb15 Installation of ConfigMgr(SCCM) 2012 RC2

image thumb16 Installation of ConfigMgr(SCCM) 2012 RC2

Use Prereq Checker setup file before you start the installation of configuration manager 2012

K:\Kit\SCCM Kit\SCCM 2012\ConfigMgr_2012_RC2_ENU_7703\SMSSETUP\BIN\X64>prereqchk.exe /ADMINUI

After installing all the prereq files including IIS,BITS,Schema extension,RDC and dotnet 4.0 Full.

image thumb17 Installation of ConfigMgr(SCCM) 2012 RC2

image thumb23 Installation of ConfigMgr(SCCM) 2012 RC2

image thumb24 Installation of ConfigMgr(SCCM) 2012 RC2

For administering and configuring configMgr 2012 ,please look Windows-noob.com

http://www.windows-noob.com/forums/index.php?/topic/4045-sccm-2012-guides/

Additional Resources

Tags: , , , , , , , , , , ,
Posted in Maintanance windows, SCCM 2007, SCCM 2012, Task Sequence | 4 Comments »

SCCM 2012 Site System Roles & What is new in SCCM 2012 :

Posted by Eswar Koneti on 22nd January 2012

Configuration Manager uses site system roles to support management operations at each site. When you install a Configuration Manager site, some site system roles are automatically installed and assigned to the server on which Configuration Manager Setup has run successfully. One of these site system roles is the site server, which you cannot transfer to another server or remove without uninstalling the site. You can use other servers to run additional site system roles or to transfer some site system roles from the site server by installing and configuring Configuration Manager site system servers.

Each site system role supports different management functions. The site system roles that provide basic management functionality are described in the following .

Below are total available(18) site system roles in ConfigMgr 2012:

Component Server :Any server that runs the SMS Executive service. A server that runs Configuration Manager services. When you install all the site system roles except for the distribution point role, Configuration Manager automatically installs the component server.

Site Server : A computer on which you run the Configuration Manager setup program and which provides the core functionality for the site.

Site System: A server or server Share that hosts one or more site system roles for Configuration Manager site

Site Database Server :A site system role that runs Microsoft SQL server and hosts the configuration Manager Site Database

Management Point :A site system role that replies to configuration Manager Clients requests and accepts management data from configuration manager clients

Distribution Point :A configuration manager role that stages packages for Distribution to clients

Application Catalog Website Point:A site system role that serves as an application catalog website point

Application Catalog Web service point :A site system role that serves as application catalog web services point

Asset Intelligence Synchnozation Point :A site system role that connects to system center online to download asset intelligence catalog information and upload uncategorized titles that can be considered for future inclusion in the catalog

End Point Protection Point :A site system role that serves as end point protection

Enrollment Point :A site system role that enables enrollment for mobile devices and AMT functionality

Enrollment Proxy Point:A site system role that communicates with mobile devices during enrollment

Fallback Status Point:A site system role that receives messages from configmgr clients that can not communicate with their management point

Out of band service point : A site system role that provisions and configures Intel AMT-based computers for out of band management.

Reporting services Point :A site system role that provides integration with SQL server reporting services to create and manager reports for configuration manager

Software update point :A site system role that runs Microsoft widows server update services and allows configuration manager to use the WSUS catalog to scan configuration manager clients for software updates

State migration Point :A site system role that store user state and settings migrated during the Operating system deployment

system health Validator Point :settings for all system health validator point in their site such as statement of health validation and configuration manager health state references.

TechNet Reference for Install and Configure Configuration Manager site system Roles in ConfigMgr 2012 http://technet.microsoft.com/en-us/library/hh272770.aspx

The following site systems roles are removed:

  • The reporting point. All reports are generated by the reporting services point.
  • The PXE service point. This functionality is moved to the distribution point.
  • The server locator point. This functionality is moved to the management point.
  • The branch distribution point. Distribution points can be installed on servers or workstations that are in an Active Directory domain. The functionality of the branch distribution point is now a BranchCache setting for an application deployment type and the package deployment.

In addition, you no longer configure network load balanced (NLB) management points. This functionality is automatically provided when you install more than one management point in the site.

The following site system roles are new:

  • The Application Catalog website point and the Application Catalog web services point. These site system roles require IIS and support the new client application, Software Center.
  • The enrollment proxy point, which manages enrollment requests from mobile devices, and the enrollment point, which completes mobile device enrollment and provisions AMT-based computers. These site system roles require IIS.

There is no longer a default management point at primary sites. Instead you can install multiple management points and the client will automatically select one, based on network location and capability (HTTPS or HTTP). This behavior supports a higher number of clients in a single site and provides redundancy, which was previously obtained by using a network load balancing (NLB) cluster. When the site contains some management points that support HTTPS client connections and some management points that support HTTP client connections, the client will connect to a management point that is configured for HTTPS when the client has a valid PKI certificate.

You can also have more than one Internet-based management point in a primary site, although you can specify only one when you configure clients for Internet-based client management. When Internet-based clients communicate with the specified Internet-based management point, they will be given a list of all the Internet-based management points in the site and then select one.

At a secondary site, the management point is no longer referred to as proxy management point, and must be co-located on the secondary site server.

Tags: , , , , , , , , , , , ,
Posted in Documentation, SCCM 2007, SCCM 2012 | 4 Comments »

The Hydration Kit for ConfigMgr 2012 RC2 is available for download

Posted by Eswar Koneti on 20th January 2012

Here is a download for deploying a complete ConfigMgr 2012 RC2 (which was release recently http://eskonr.com/2012/01/configmgr-2012-rc2-released/)  infrastructure in either Hyper-V or VMware: One Domain Controller and one ConfigMgr 2012 RC2 member server – Including pre-requisites like .Net Framework, SQL 2008 R2 SP1 CU4 and IIS – all fully automated.
Once configured, the total build time for the full ConfigMgr 2012 RC2 lab environment is about 1.5 hours (on my laptop).
Download the Hydration Kit for ConfigMgr 2012 RC2 (137 kb).

Full post, Please Read Via http://www.deploymentresearch.com/Blog/tabid/62/EntryId/49/The-Hydration-Kit-for-ConfigMgr-2012-RC2-is-available-for-download.aspx

Additional Resources

Tags: , , , , , ,
Posted in SCCM 2012, Scripting | No Comments »

How to Fix WMI issues automatically

Posted by Eswar Koneti on 20th January 2012

While Ago I have posted a solution on how to fix WMI(Windows Management Instrumentation) issues using simple batch script that stops WMI service and recompile all MOF files etc. http://eskonr.com/2009/03/how-to-troubleshoot-the-systems-which-has-wmi-issues-rebuild-wmi-repository/

While working with new windows 7 migration project, we had lot of computers with wmi issue but how to identify which has wmi and fix it automatically. There could be various reasons if configmgr client is not reporting to site server but wmi issue one of major problem .if wmi issue occur, nothing can be performed on configmgr client. No policies, no inventory information nothing will be received or sent to MP.

It would be difficult to identify machines which as WMI corruption so either you can apply wmi script Via GPO to run every time when computer boots up else go with psexec to run the script remotely or different methods which you would prefer.

I come up with simple script that check the functionality of WMI if WMI is working fine, exit the script else repair WMI functionality.

This script you can apply through Logon or make it on schedule basis to run every twice or run once a day through Task Scheduler job on all the machines http://msdn.microsoft.com/en-us/library/windows/desktop/aa383614(v=vs.85).aspx

WMI Isn’t Working! ? http://technet.microsoft.com/en-us/library/ff406382.aspx

Here is out Batch script that check the functionality of wmi using simple wmic command:

wmic computersystem get name

if the the above command gives any output,script exit else repair it.

Here is the complete Batch script :

REM Check if WMI is functioning correctly or not

REM Get computername from WMI

wmic computersystem get name

IF %ERRORLEVEL% EQU 0 goto success

:failure

net stop ccmexec /y

net stop VMAuthdService /y

net stop winmgmt /y

c:

cd %systemroot%\system32\wbem

rd /S /Q repository

regsvr32 /s %systemroot%\system32\scecli.dll

regsvr32 /s %systemroot%\system32\userenv.dll

mofcomp cimwin32.mof

mofcomp cimwin32.mfl

mofcomp rsop.mof

mofcomp rsop.mfl

for /f %%s in (‘dir /b /s *.dll’) do regsvr32 /s %%s

for /f %%s in (‘dir /b *.mof’) do mofcomp %%s

for /f %%s in (‘dir /b *.mfl’) do mofcomp %%s

net start winmgmt

net start VMAuthdService

net start ccmexec

goto end

:success

goto end

:end

Some theory about WMI and how to check if it is working or not.

What is WMI (windows management Instrumentation)?

Windows Management Instrumentation (WMI) is the infrastructure for management data and operations on Windows-based operating systems

WMI can be used in all Windows-based applications, and is most useful in enterprise applications and administrative scripts

For example, you can:

· Start a process on a remote computer.

· Schedule a process to run at specific times on specific days.

· Reboot a computer remotely.

· Get a list of applications installed on a local or remote computer.

· Query the Windows event logs on a local or remote computer.

How to connect to WMI (local or remote computer):

Type wbemtest from Run command

clip image001 thumb How to Fix WMI issues automatically

clip image002 thumb How to Fix WMI issues automatically

Click on Connect

clip image003 thumb How to Fix WMI issues automatically

The Default Name space is root\cimV2 .You have many namespaces available in WMI.

Click on Connect

clip image004 thumb How to Fix WMI issues automatically

Click on Enum Classes

clip image005 thumb How to Fix WMI issues automatically

Select Recursive

clip image006 thumb How to Fix WMI issues automatically

You can see lot of classes available for cimV2 name space. For more information about available classes in WMI namespace called cimV2 ,please look at here http://msdn.microsoft.com/en-us/library/windows/desktop/aa394084(v=vs.85).aspx with its description and objects within it.

Now you can see all the classes available within cimV2 name space.

To know more about what each class contains and its objects with in it

Double click on any class which you want to look at it and click on name which you desire

clip image007 thumb How to Fix WMI issues automatically

Now we will see how to execute to get required information with in WMI:

Go back to namespace called cimV2 shown below :

clip image008 thumb How to Fix WMI issues automatically

Click on Query:

clip image009 thumb How to Fix WMI issues automatically

Click on apply to see the results. You can execute any query which has correct syntax to get the correct information.

How do you run wbemtest on remote computer?

1. To connect remotely using tools like CIM Studio or Wbemtest, you must specify a namespace in the form “\\<machinename>\root\<namespace>”
For example: \\mymachine\root\cimv2 as shown below and perform the steps whatever you need as did above.

2. clip image010 thumb How to Fix WMI issues automatically

How do you check remotely if WMI is working well or not ?

You do it via wbemtest or wmimgmt.msc from run command

clip image011 thumb How to Fix WMI issues automatically

clip image012 thumb How to Fix WMI issues automatically

clip image013 thumb How to Fix WMI issues automatically

clip image015 thumb How to Fix WMI issues automatically

 

clip image017 thumb How to Fix WMI issues automatically

clip image018 thumb How to Fix WMI issues automatically

See the error above. The RPC server is unavailable means something wrong with the computer could be machine doesn’t not exist on the network or name resolution or permission issue etc

If computer is connect successfully and if you look at properties of the computer ,you will see the below screen,

clip image019 thumb How to Fix WMI issues automatically

For more information about WMI Faqs ,please refer this guide http://technet.microsoft.com/en-us/library/ee692772.aspx

Reference Guides on WMI troubleshooting: http://eskonr.com/2009/03/how-to-troubleshoot-the-systems-which-has-wmi-issues-rebuild-wmi-repository/

http://blogs.technet.com/b/configmgrteam/archive/2009/05/08/wmi-troubleshooting-tips.aspx

Reference http://social.technet.microsoft.com/Forums/en-US/configmgradminconsole/thread/a9922b7f-3b81-4b2b-866a-423106b0e9fe

Feel Free to post your comments.

Tags: , , , , , , , , , , , ,
Posted in SCCM 2007, SCCM 2012, Scripting, Trobleshooting Tips, Troubleshooting Issues, WMI | 7 Comments »

ConfigMgr 2012 RC2 released

Posted by Eswar Koneti on 18th January 2012

System center configuration Manager 2012 RC2 is released and avilable to download now.

It will be available from the System Center Eval Center:

http://technet.microsoft.com/en-us/evalcenter/hh505660.aspx 

I have tried it downloading but i can see other components along with System center configmgr 2012 with all the links avilable to download.

if you are looking for only System center configuration manager 2012 RC2, you can use this link to save time in downloading other components http://care.dlservice.microsoft.com/dl/download/3/4/C/34C7656A-F89E-473C-8CE0-21DA5DB0717C/configmgr_2012_RC2_ENU_7703.exe else you can pause/cancel from your download manager tool.

SCCM 2012 Download 300x97 ConfigMgr 2012 RC2 released

 Additional Resources

Tags: , , , , ,
Posted in SCCM 2012 | No Comments »

Blog Review For 2011

Posted by Eswar Koneti on 10th January 2012

To kick off the new year, I’d like to share with you data on my blog’s activity in 2011. You may start scrolling!

Crunchy numbers :

In 2011, there were 33 new posts, growing the total archive of this blog to 144 posts.

The busiest day of the year was December 21st . The most popular post that day was SCCM Tips and Tricks.

How did they find eskonr.com?

Some visitors came searching, mostly for eswar koneti, reporat distribution packages failed, sccm laptop collection, and mdt prompt for computer name.

Where did they come from?

 where did they come from1 300x105 Blog Review For 2011

Most visitors came from The United States. India & The United Kingdom were not far behind.

Attractions in 2011:

These are the posts that got the most views in 2011. You can see all of the year’s most-viewed posts in your Site Stats.

Thank you all and Hope you have enjoyed the technical stuff avilable from this Blog.Hope we do many things this year with the new release of system Center Configuration Manager 2012 (ConfigMgr 2012) http://technet.microsoft.com/en-us/library/gg682140.aspx and other system Center Technologies.

Tags: , , ,
Posted in Awards, Documentation | No Comments »

Troubleshooting an issue where ConfigMgr Active Directory Discovery from a Secondary Site to another Forest fails

Posted by Eswar Koneti on 10th January 2012

We’ve seen this issue come up a couple of times so I wanted to give it a mention here just in case you run into it. The problem is that you may notice that a System Center Configuration Manager 2007 (ConfigMgr 2007) Secondary Site Server is unable to do any type of AD discovery in another forest. The forest trust is working fine, and you may see some errors in the adsysdis.log on the secondary site server similar to the following:

ERROR: Failed to bind to ‘LDAP://domainname/rootDSE’ (0x8007203B)
ERROR: Failed to enumerate directory objects in AD container LDAP://FQDN SMS_AD_SYSTEM_DISCOVERY_AGENT 11/16/2011 1:41:10 PM 4688 (0×1250)
STATMSG: ID=5204 SEV=E LEV=M SOURCE=”SMS Server” COMP=”SMS_AD_SYSTEM_DISCOVERY_AGENT” SYS=machine name SITE=site name PID=2252 TID=4688 GMTDATE=Wed Nov 16 19:41:10.771 2011 ISTR0=”LDAP://FQDN” ISTR1=”A local error has occurred.~~” ISTR2=”" ISTR3=”" ISTR4=”" ISTR5=”" ISTR6=”" ISTR7=”" ISTR8=”" ISTR9=”" NUMATTRS=0 SMS_AD_SYSTEM_DISCOVERY_AGENT 11/16/2011 1:41:10 PM 4688 (0×1250)

Troubleshooting

We checked the trust between the two forests, we have forest trust, and found the trust to be working just fine. I was able to access the resources or the users of the either forest.

The Central site server and the Primary site server were able to do any type of AD discovery fine from any other trusted forests.

We then found the following error in the adsysdis.log which seems to point to an authentication issue:

ERROR: Failed to bind to ‘LDAP://domainname/rootDSE’ (0x8007203B)
ERROR: Failed to enumerate directory objects in AD container LDAP://FQDN

We examined and found the DNS name resolution to be working fine on the secondary site server so we then enabled Netmon to take a network capture. After triggering adsysdis.dll by running the AD system discovery we found the following errors in the Netmon trace:

0 2389 2:42:40 AM 12/17/2011 67.9452322 10.136.1.12 10.136.1.13 TCP TCP:Flags=…A..S., SrcPort=Kerberos(88), DstPort=57753, PayloadLen=0, Seq=2509066299, Ack=1957022246, Win=64240 ( Negotiated scale factor 0×0 ) = 64240
0 2390 2:42:40 AM 12/17/2011 67.9452487 10.136.1.13 10.136.1.12 TCP TCP:Flags=…A…., SrcPort=57753, DstPort=Kerberos(88), PayloadLen=0, Seq=1957022246, Ack=2509066300, Win=513 (scale factor 0×8) = 131328
1595 2391 2:42:40 AM 12/17/2011 67.9452920 10.136.1.13 10.136.1.12 KerberosV5 KerberosV5:TGS Request Realm: DOMAIN.LOCAL Sname: ldap/srv-msk-dc.domain.local/domain.local
0 2392 2:42:40 AM 12/17/2011 67.9453753 10.136.1.12 10.136.1.13 TCP TCP:Flags=…A…., SrcPort=Kerberos(88), DstPort=57753, PayloadLen=0, Seq=2509066300, Ack=1957023841, Win=64240 (scale factor 0×0) = 64240
172 2393 2:42:40 AM 12/17/2011 67.9462934 10.136.1.12 10.136.1.13 KerberosV5 KerberosV5:KRB_ERROR – KDC_ERR_POLICY (12)
0 2394 2:42:40 AM 12/17/2011 67.9463337 10.136.1.13 10.136.1.12 TCP TCP:Flags=…A…F, SrcPort=57753, DstPort=Kerberos(88), PayloadLen=0, Seq=1957023841, Ack=2509066472, Win=512 (scale factor 0×8) = 131072
0 2395 2:42:40 AM 12/17/2011 67.9463952 10.136.1.12 10.136.1.13 TCP TCP:Flags=…A…., SrcPort=Kerberos(88), DstPort=57753, PayloadLen=0, Seq=2509066472, Ack=1957023842, Win=64240 (scale factor 0×0) = 64240
0 2396 2:42:40 AM 12/17/2011 67.9464449 10.136.1.12 10.136.1.13 TCP TCP:Flags=…A.R.., SrcPort=Kerberos(88), DstPort=57753, PayloadLen=0, Seq=2509066472, Ack=1957023842, Win=0 (scale factor 0×0) = 0
12 2397 2:42:40 AM 12/17/2011 67.9465423 System 10.136.1.13 10.136.1.12 LDAPMessage LDAPMessage:Unbind Request, MessageID: 803
0 2398 2:42:40 AM 12/17/2011 67.9465752 System 10.136.1.13 10.136.1.12 TCP TCP:Flags=…A…F, SrcPort=57752, DstPort=LDAP(389), PayloadLen=0, Seq=1915435841, Ack=3623185621, Win=513 (scale factor 0×8) = 131328

Everything seemed to be setup fine and the trust is also working fine. Also this problem did not affect all ConfigMgr 2007 site servers, but only this secondary site server.

Cause

It turns out that this issue was due to the “Selective authentication trust” between these two forests, as in the case of the Selective authentication trust the secondary site server or any other object has to be given required permissions manually in the other forests domain exclusively.

Solution

Once you manually give permissions to the secondary site server machine account in the other forest domain’s active directory, and then purge the old Kerberos tickets using the klist tool from the secondary site server or restart the secondary site server, the server gets the new ticket and the new access token which have the new permissions to enumerate the other forests Active Directory to do any type of discovery (as we know that the machine account is used for discoveries).

More Information

This problem can also manifest itself in other ways such as when the central or the primary or any other machine is not able to see or access the resources from the other forests or domains. This issue can be fixed by manually giving the permissions to that object on the desired resource. In the case of Selective authentication trust though the forest trust you can even validate it, but the trust is only for the objects that have been given permissions manually to the resource. In a case of Discovery, the adsource.dll impersonates itself as the machine account of the site server, so the machine account should have the right permissions in Active Directory.

The TechNet article below articulates the permissions required and the complete flow of all type of the discoveries in ConfigMgr 2007:

http://technet.microsoft.com/en-us/library/bb632733.aspx

Arvind Rana

Via http://blogs.technet.com/b/configurationmgr/archive/2012/01/09/troubleshooting-an-issue-where-configmgr-active-directory-discovery-from-a-secondary-site-to-another-forest-fails.aspx

Tags: , , , , , , ,
Posted in SCCM 2007 | No Comments »

configMgr collection do not contain letters in it

Posted by Eswar Koneti on 21st December 2011

The collection listed below might help you to identify if any computers in organization that do not follow the standard naming convention .

Below collection is created to list servers and do not contain specific words in computer name:

select SMS_R_System.Name, SMS_R_System.OperatingSystemNameandVersion from  SMS_R_System where (SMS_R_System.OperatingSystemNameandVersion like “%Server 6.%” or SMS_R_System.OperatingSystemNameandVersion like “%Server 5.%”) and SMS_R_System.ResourceId not in (select ResourceID  from  SMS_R_System where SMS_R_System.Name like “%xxx%”)

The Logic is : list all servers with criteria given above and computer do not have xxx word in it.

Please change the bold letters as per the requirement.

 

Tags: , , , , , , ,
Posted in Collections, SCCM 2007, WQL Quiries | No Comments »

SCCM collection Sub selected Quiries

Posted by Eswar Koneti on 2nd December 2011

Have seen lot of questions on how to get list of computers that do not have xxxxxx .This xxxx could be of anything like softwares,file names anything that do not have.

In this post,I will go through step by step procedure how to make it simple.

Step 1: To get list of computers that do not have xxxx,create a collection query that has xxxx. I think this is pretty much easy how to do it using criteria.

Create new collection and edit the query .

Subselected quiries 1 271x300 SCCM collection Sub selected Quiries

Click on Criteria Tab , click Yellow Burst

Subselected quiries 2 269x300 SCCM collection Sub selected Quiries

In the Criterion properties page, click on select

Subselected quiries 3 266x300 SCCM collection Sub selected Quiries

select attribute class and attribute which you want ( here i go with add and remove programs)

Subselected quiries 4 300x177 SCCM collection Sub selected Quiries

 

select the display name which you like xxxxx .I go with Adobe Acrobat .Why i used % is ,it list all computers that contains word like Adobe Acrobat.

Subselected quiries 5 268x300 SCCM collection Sub selected Quiries

Now Click on Show query Language to get the WQL code:

Subselected quiries 6 269x300 SCCM collection Sub selected Quiries

Here is the code we have got that list all computers with particular software installed :

select *  from  SMS_R_System inner join SMS_G_System_ADD_REMOVE_PROGRAMS on SMS_G_System_ADD_REMOVE_PROGRAMS.ResourceId = SMS_R_System.ResourceId where SMS_G_System_ADD_REMOVE_PROGRAMS.DisplayName like “%Adobe Acrobat%”

so cut the query and paste it in notepad we need this again.You will see blank query now.

Subselected quiries 7 269x300 SCCM collection Sub selected Quiries

Step 2: In this step,we will create collection with subselected criteria to get what we need .

Click on the Yellow Burst once again and select criterian type as “Subselected Values” and click on select

Subselected quiries 8 270x300 SCCM collection Sub selected Quiries

 

Subselected quiries 9 300x178 SCCM collection Sub selected Quiries

 

and select the operator as not in and past the query which you copied earlier into it.

Subselected quiries 10 270x300 SCCM collection Sub selected Quiries

 

query which we created earlier is :

select *  from  SMS_R_System inner join SMS_G_System_ADD_REMOVE_PROGRAMS on SMS_G_System_ADD_REMOVE_PROGRAMS.ResourceId = SMS_R_System.ResourceId where SMS_G_System_ADD_REMOVE_PROGRAMS.DisplayName like “%Adobe Acrobat%”

Replace * with SMS_R_System.ResourceID in your qeury and click on Ok.

Subselected quiries 11 267x300 SCCM collection Sub selected Quiries

 You can also filter the above collection to look only for windows 7 computer i.e OS version 6.1 etc .

Tags: , , , , , , , ,
Posted in Collections, SCCM 2007, WQL Quiries | No Comments »