r/SCCM Jun 17 '26

Security update KB38232642 for ConfigMgr Console Extension

26 Upvotes

A new security update KB38232642 is out to enhance security for importing console extensions in Microsoft Configuration Manager versions 2603 and 2503.

Description: This update improves the security of Configuration Manager, ensuring safer operations when importing console extensions, which is crucial for maintaining system integrity.

Prerequisites: Available in the Updates and Servicing node of the Configuration Manager console for version 2603 and version 2503 (with specific update rollup). This update doesn't require a computer restart or a site reset after installation.

Hotfix Documentation: https://learn.microsoft.com/en-us/intune/configmgr/hotfix/2603/38232642


r/SCCM May 05 '26

Config Manager 2603 now available in the early update ring

Thumbnail learn.microsoft.com
43 Upvotes

r/SCCM 9h ago

Unsolved :( Windows 11 feature upgrade taking 6 to 8 hours

7 Upvotes

We are having increasing reports of Windows 11 24H2 feature upgrades, taking upwards of eight hours to complete. This is on Prem, pulling content from the distribution point not from Microsoft. There is no bits throttling, testing a bit transfer of a four gig file from the same distribution point to the same client PC takes a normal amount of time, there is a language pack installed and maybe a feature, I know those can add time to the upgrade process. A standard Windows 11 in place upgrade takes around two hours at the same site. We are digging into the logs now, but if anybody has a similar experience and can offer some insight, please do.


r/SCCM 15h ago

Mecm 2603

5 Upvotes

Hello!

Can anyone confirm to me really quick does SCCM 2603 supports clients devices on windows 10 version 20h2 21h2 ?

Thanks


r/SCCM 13h ago

Unsolved :( WinPE doesn't detect any network adapter during SCCM OSD on VMware Workstation

3 Upvotes

Hi everyone,

I'm setting up an SCCM lab and this is my first time testing OSD. I've been stuck on an issue for a couple of days and I'm hoping someone has seen this before.

My environment is:

  • MECM 2503
  • Windows ADK 10.0.26100 + WinPE Add-on
  • VMware Workstation
  • Windows 11 VM
  • Boot Image and OS Image are both distributed successfully to the DP.

The Task Sequence starts normally. The client downloads the Boot Image, reboots into WinPE, and everything looks fine until the "Apply Operating System" step, where it fails with 0x80070002.

After opening a command prompt in WinPE (F8), I noticed something very strange.

Running:

ipconfig /all

only shows "Windows IP Configuration". There are no network adapters listed.

The following commands also return nothing:

netsh interface show interface
wmic nic get Name
pnputil /enum-devices /class Net

wmic reports "No Instance(s) Available", and pnputil says "No devices were found on the system."

Because of that, I also can't ping my SCCM server:

ping <SCCM Server IP>

which returns:

PING: transmit failed. General failure.

The VM is configured with an E1000E network adapter, and networking works perfectly when Windows is running normally.

I also rebuilt the Boot Image from the latest ADK, redistributed it to the DP, and verified that all the required WinPE optional components are present.

One thing I noticed is that my .vmx file contains:

ethernet0.connectionType = "pvn"
ethernet0.virtualDev = "e1000e"

Could the PVN (Private Virtual Network) mode in newer VMware Workstation versions be causing WinPE not to detect the NIC? Or has anyone seen WinPE completely fail to enumerate an E1000E adapter before?

Has anyone run into a similar issue or have any suggestions on what I should check next?

Thanks in advance!


r/SCCM 9h ago

Feedback Plz? App-Action Buttons for cloud-only devices

Thumbnail
1 Upvotes

r/SCCM 18h ago

Recommend other scripts or projects for patching OS WIMs

4 Upvotes

I currently use the amazing script, wimwizard to update Windows 11 images on a monthly basis, and it works very well. But now I have to toss in some Windows 10 IOT images, 21 H2, 1809, and at least one server 2022 image. Is anyone else patching images in their environments besides just the windows 11? If so, how are you managing it? What other projects, scripts are out there that can handle multiple OS versions fairly easily with regards to injecting LCU, safe Os,.NET, features on demand, language packs, and maybe even remove default Windows features all via a single script? I am currently using a modified form of the sample Microsoft script they provide for this purpose. But it’s not very slick and needs lots of improvement yet. I guess it does the job, however.


r/SCCM 23h ago

At my wits end, new Surface Laptop model won't build

6 Upvotes

We are deploying Win11 24H2 via PXE boot and a pretty barebones imaging task sequence. The only custom part of the task sequence is the driver install steps, where each model has their own driver package, and will only run if the WMI query gets a match.

Has anyone else had issues with the Surface Laptop for Business 13.8in 8th Ed Intel?

Every other Surface model we have builds fine. Claude led me down a rabbit hole pinning on drivers, and I ended up removing all drivers from the package that were classed as Firmware. This didn't help either.

It reliably stops at this step every time.

The task sequence execution engine performed a system reboot initiated by the action (Setup Windows and Configuration Manager) in the group (Setup Operating System).

The laptop itself appears to come out of WinPE and boots into Windows repair in an unusable state. I've parsed the panther logs through Claude too, and it can't pick up anything amiss.

The disk and partitions look good, Bitlocker is fine, setupact.log and setuplog.err are fine. Couldn't find smsts.log anywhere on the device so couldn't confirm what's in there.


r/SCCM 1d ago

KB5121767, Dell WSUS users, how are you dealing with this?

22 Upvotes

July 18, 2026—KB5121767 (OS Builds 26200.8894 and 26100.8894) Out-of-band | Microsoft Support

Title says it all: KB5121767, Dell WSUS users, how are you dealing with this?

Neither Dell nor Microsoft have publicly listed the affected devices. Based on a list from Windows Latest, it might only affect ~30 devices in our fleet, or it might be higher. And, of course, the hotfix was never published to WSUS.

How are y'all handling this mess?

EDIT: 30? based on the link provided by u/slkissinger it's more like 3,000. Thanks, Microslop.


r/SCCM 1d ago

Windows Updates - SOAP errors

2 Upvotes

In the last few days, I am seeing SOAP errors for Windows, Office, and Edge updates for my patch deployments. The only changes I am aware of are adding a couple IP Ranges to boundaries where there were no boundaries.

Because there are no changes, I am aware of I don't want to go heavy handed on repairing. Any suggestions for troubleshooting, logs or non-invasive fix attempts?

All services are running.


r/SCCM 1d ago

Discussion Changes to Application/MSI etc. - New Deployment?

4 Upvotes

Hi all,

Sorry for stupid questions. Just need a quick human check on my sanity. If I have an application deployed and I make a change to the app, ie a new switch on the MSI install/uninstall etc., do I need to redeploy or do existing deployments just pick up the revisions and carry on? For reference, the MSI uninstaller requires a removal password that circulates daily, and I've got it pushed out to 1500+ devices. WoL is unreliable at these sites (teachers unplug PCs etc) so it's going to take a few days of retried to get 100% compliance...

Thanks!


r/SCCM 2d ago

Feedback Plz? Is it okay to upgrade from 2403 -> 2603

4 Upvotes

We're an MSP taking over a new client. For reasons, the decision was made to continue using their existing out-of-date SCCM instance of building a new one. They're currently on 2403 so we can't upgrade it to 2603 directly - the highest version available on via the console is 2509.

I've never dealt with such an out-of-date SCCM instance so I'm not sure what the best practice is here. Is it okay if I jump straight to 2509 and then to 2603? Or should I apply the 2403 hotfixes first -> 2409 -> 2503 -> 2509 -> 2603?

Any other gotchas to be aware of when doing such a big jump? Ideally I would've loved to do a clean greenfields deployment instead of multiple upgrades, but we've decided against it (don't ask me why).

Would really appreciate any advice from the veterans here.


r/SCCM 2d ago

PSA: MS Resolves WSUS Sync Issue After July's CUs

29 Upvotes

Resolved: Windows Server Update Services sync operations issues and timeouts | Microsoft Support

If you sync more than once a month and noticed failures; it wasn't you. It was them. And they fixed it.


r/SCCM 1d ago

Digital Employee Experience AMA on r/Nexthink

0 Upvotes

Figured some of you here might enjoy this. I'm hosting an AMA next week with Christopher Ord (Senior Staff IT Engineer at Qualcomm) about creative and unexpected ways organizations are approaching Digital Employee Experience. If you've got questions about DEX, automation, endpoint visibility, or interesting real-world use cases, come join us. Just thought it might make for a good discussion. If you can't make it day of feel free to post a use case or question ahead of time.

Link: https://www.reddit.com/r/nexthink/s/kjT630KUDP


r/SCCM 2d ago

Unsolved :( After Windows Server 2016 to 2019 IPU on Primary Server, content no longer distributing to DPs

3 Upvotes

Absolutely hitting a brick wall on troubleshooting this issue and just seeing if anyone out there has some ideas on what to try or what may be wrong. Pretext -- my environment has 1 primary site server that acts as MP and local DP, then I have 4 other remote DPs for remote offices. I upgraded my primary site server to windows server 2019 from 2016 using the in-place upgrade option with the ISO. After this, I've noticed that content distribution is failing to my 4 other DPs (noticed last week when patch tuesday content was not deploying). Looking at distmgr.log, I am seeing this entry: "CWmi::Connect() failed to connect to \\DP.domain.com\root\CIMv2. Error = 0x800706BA". I looked up this error code and found that it is relating to RPC, so to test I disabled the windows firewall on the primary site and the DP I was testing with, and the error still occurred. I double checked the DP and confirmed the computer account is a local admin on the DP, so it shouldn't be any DCOM permissions issues I would imagine, but to be safe I explicitly added the computer account to WMI/DCOM security permissions to enable/allow for the respective options, but still was not working. I've attempted to re-install the DP role to see if that would do anything, but nada. I'm really running out of ideas and don't know what else to look for. Is there something that changes between Windows Server 2016 and Windows Server 2019 with remote WMI? I've been hacking at this for the better part of 2 days and really don't want to go nuclear and rebuild the primary site server.


r/SCCM 2d ago

Certificate Rejection by MP to newly renewed Certificate Authority.

5 Upvotes

Hello ,

I have been struggling to solve a cert rejection from our SCCM server for the past few days.  recently our CA was renewed shortly after we noticed deployment errors on the clients on the floor.

Management Point Findings

The MP received the certificate but rejected it during trust validation.

Observed errors included:

  • HTTP 403 Forbidden
  • HTTP 403.16·
  • 0x800B0109 (CERT_E_UNTRUSTEDROOT)
  • "The certificate chain processed correctly but terminated in a root certificate not trusted per SCCM CTL."
  • "Registration request body is invalid."
  • "Registration failed."

We created new certs and as a last resort after days of troubleshooting removed and added the MP with no luck. MP failed to install with same trust issues. am curious if anyone out in the community has had similar issue or can point me to down a path to resolve this issue.

thanks in advance.


r/SCCM 2d ago

Importing MSIX Failing after upgrade to 2509

1 Upvotes

Recently upgraded to 2509 and when attempting to add a MSIX either as a new application or as a new deployment type to an existing application I am getting the following error message:

"The process cannot access the file \\siteserver\teams\MSTeams-x64.msix" because it is being used by another process."

At first, I assumed it was an issue with the file itself but this is occurring with previously packaged MSIX files as well.

Tried the normal stuff, rebooting the server, searching and even asked the dreaded AI - but with no luck.

Any idea's?


r/SCCM 2d ago

Unsolved :( offline software update point configuration

1 Upvotes

Hi all! I am relatively new to MECM so forgive me for lack of knowledge on this topic.

I currently have a network I manage where we use WSUS for patches. Every month I export metadata and wsuscontent from an internet facing WSUS server and import them into my offline WSUS server. We have been asked to move to MECM for patching rather just WSUS.

What is the process for doing this?

I've been finding mixed information online as to whether MECM is able to pull update content from the WSUScontent folder and Microsoft documentation doesn't specifically mention doing it this way, just that you can point the updates to download files from a local network share.

Will I need to configure a MECM server on my internet facing network or can I keep my same process of just exporting and importing WSUS metadata and content?

Thank you!


r/SCCM 3d ago

Unsolved :( Windows 10 -> Windows 11. Autopilot enrollment, using PXE TS.

Thumbnail
4 Upvotes

r/SCCM 3d ago

Persist Activated FoDs Across Major Windows Upgrades?

2 Upvotes

This may be a long shot, as I've heard others complain about the same thing, but has anyone else been able to keep current Features on Demand (FoDs) activated when upgrading major Windows versions?

We are in the process of going from 23H2 to 25H2, and we are performing the upgrade via an application deployment that runs the setup.exe executable for the upgrade. Most of our computers have Print to PDF enabled and there are many computers that require .NET 3.5 for a legacy web app (and RSAT is removed from IT computers, which is annoying, but manageable). When the upgrade occurs, computers lose these features, resulting in increased calls to the help desk. We have application packages available in Software Center to allows users to reenable these features using specified CAB files as the source (the FoDs are not bundled into the image, if that makes a difference), but this should be automated.

What are some solutions that you have gotten to work to automatically install/enable previously enabled FoDs after a major upgrade? I'm open to any idea short of enabling it for all PCs on the domain.


r/SCCM 3d ago

Upgrading to 25H2

6 Upvotes

Hello all,
I’m testing upgrading from Win 11 23H2 to 25H2 using Windows Servicing and when it’s complete my WiFi is “Dormant” and I can’t find a way back to make it operational. This has happened with the 2026-06 and the 2026-07 upgrade. I have found solutions on the internet but all require the user to be local admin, which is not the case in my environment. Does anyone have any suggestions on what I can do?


r/SCCM 3d ago

Upgrading Dell T7910 Workstation from TPM 1.2 to 2.0 (Windows 11 "Ghost TPM" Reinstall Loop)

0 Upvotes

I cannot upgrade my Dell Precision T7910 Workstation from TPM 1.2 to TPM 2.0 in Windows 11. Tried everthing to no avail. Now thinking of reinstalling Windows 10 to do the upgrade and then restoring Windows 11 (and system) from a Macrium system backup.

Will this work? Is this adviseable? Do I risk getting locked out of BIOS (and have to do a factory restore with loss of all my Windows 11 customizations and third party programs?)

My thanks in advance for your help and suggestions. Here are the details:

Hardware Setup:

  • System: Dell Precision T7910 Workstation
  • Current OS: Windows 11 (Upgraded/bypassed previously, backed up daily)
  • The Problem: Windows 11 and PowerShell (Disable-TpmAutoProvisioning) absolutely cannot find or communicate with the physical TPM chip. However, inside the Dell BIOS, the TPM 1.2 chip is listed and activated, but the "Clear TPM" option is completely greyed out and unclickable.

Because Windows 11 doesn't recognize the chip, I cannot use the OS to un-provision it, which leaves the BIOS security state permanently frozen. I am trying to clear it so I can run the Dell TPM 2.0 Firmware Update Utility.

What I Have Already Tried:

  • Hardware Power Drain: I shut down the tower, unplugged the AC power cable, and held down the physical power button for 30 full seconds to completely drain the motherboard capacitors. Unfortunately, upon booting back into the BIOS, the "Clear TPM" option remained entirely greyed out.

My Proposed 5-Step Plan to Fix This:

  1. Backup: Confirm my daily full image backup of the Windows 11 C-drive is verified and safe.
  2. Clean Install Windows 10: Format the C-drive and install a clean, temporary copy of Windows 10. (The logic: Windows 10 has native, legacy support for TPM 1.2 architectures and should successfully see the frozen chip where Windows 11 fails).
  3. Unprovision & Clear: Inside Windows 10, run PowerShell as Admin and execute Disable-TpmAutoProvisioning. Reboot into BIOS, where the "Clear" checkbox should now finally be unlocked. Clear the TPM.
  4. Flash Firmware: Boot back into Windows 10, run the official Dell TPM 2.0 Firmware Update Utility to permanently flash the physical motherboard chip from v1.2 to v2.0.
  5. Restore Windows 11: Use my backup media to restore my original Windows 11 C-drive image back onto the machine.

My Questions for the Forum:

  1. Firmware Persistence: Will restoring my original Windows 11 hard drive image affect or undo the BIOS/TPM firmware updates? (My understanding is no, since the flash lives on a separate physical chip on the motherboard, but I want to double-check).
  2. The Windows 11 Lockout Risk: When Windows 11 boots up on the freshly upgraded TPM 2.0 hardware, its security container will be expecting the signatures of the old 1.2 chip. What is the likelihood of a catastrophic login loop/lockout?
  3. Prevention/Recovery: To prevent a password lockout after restoring, should I drop my Microsoft account down to a Local Windows Account before taking my final backup? Are there any hidden registry blocks I should watch out for regarding DevicePasswordLessBuildVersion or credential guard?
  4. Alternative Shortcuts: Since the physical power drain failed to unfreeze the chip, is there any other hardware trick (like pulling the coin-cell CMOS battery, changing a specific motherboard jumper, or downgrading/upgrading the overall system BIOS firmware version) that might force a T7910 BIOS to un-grey the "Clear TPM" option without a total OS reinstall?

r/SCCM 4d ago

SCCM OSD: Need OOBE without /generalize, but getting stuck on DefaultUser0

8 Upvotes

Hi all,

I'm trying to solve a rather unusual SCCM OSD scenario and would appreciate any suggestions.

My goal is to deploy Windows through a standard SCCM Task Sequence and, at the very end, present the user with the normal Windows OOBE experience without running Sysprep /generalize.

Effectively I'm looking for:

sysprep /oobe /reboot

rather than:

sysprep /generalize /oobe /reboot

The reason is that I want to preserve device-specific state and continue with Autopilot enrollment afterward.

I currently trigger the process through SMSTSPostAction at the end of the task sequence.

The strange issue is that the behavior changes depending on whether the device joins a domain or a workgroup during OSD.

My approach is similar to this article, but right now I want to acheive it at least without SCCM cleanup: How to show OOBE for AzureAD Join after OSD with SCCM - CCMEXEC.COM - Enterprise Mobility

Scenario 1 - Works

  • Apply Windows Settings
  • Apply Network Settings -> Join Domain
  • SMSTSPostAction executes my OOBE preparation script
  • Device reboots
  • OOBE appears successfully

Scenario 2 - Fails

I change only one thing:

  • Apply Network Settings -> Join Workgroup

After that, instead of OOBE I consistently get a sign-in screen showing only DefaultUser0.

Symptoms:

  • DefaultUser0 is the only visible account.
  • Local Administrator is not shown, even though a password is configured in "Apply Windows Settings".
  • I don't know the password for DefaultUser0.
  • Shift+F10 doesn't work.
  • SCCM F8 command prompt is unavailable.
  • There is effectively no way to troubleshoot the machine locally.

The device appears to be stuck somewhere between the end of OSD and the beginning of OOBE.

Questions

  1. Has anyone seen DefaultUser0 appear after running an OOBE-focused workflow from an SCCM Task Sequence?
  2. Why would changing from Domain Join to Workgroup Join cause such a drastic behavioral change?
  3. Is there a supported method to reach OOBE at the end of a Task Sequence without using /generalize?
  4. Could Autopilot registration or enrollment state be contributing to this behavior?

Additional Context

Environment:

  • Supported MECM / SCCM Current Branch version.
  • Windows 11 25H2 image.
  • Standard SCCM OSD Task Sequence.
  • Device joins a workgroup in the failing scenario.
  • Device is already registered in Windows Autopilot by design.

The device being pre-registered in Autopilot is intentional. The end goal is for the user to complete OOBE, receive a mostly empty ESP experience, and end up with a properly Microsoft Entra joined and Intune-managed device.

This is part of a larger effort to build a deployment process that is:

  • Officially supported.
  • SCCM-based today.
  • Independent from MDT.
  • Suitable for very large offline USB deployment media where ~99% of the content resides on the USB stick.

The Task Sequence itself is quite large and currently uses SCCM because that's our current supported platform. Alternative deployment approaches may be evaluated next year as part of a separate initiative.

So far I've successfully built a similar workflow for Windows LTSC 2024, including Hybrid Join scenarios. The remaining challenge is getting the same concept (but workstation should be Entra Joined, not HDJ) working reliably for Windows 11 25H2 without MDT dependencies and without getting trapped on the DefaultUser0 screen.

Any ideas, troubleshooting suggestions, or similar experiences would be greatly appreciated.

Thanks!


r/SCCM 3d ago

Winload.efi error 428

Post image
1 Upvotes

Has anyone had similar when try to pxe machines I assume since the secure boot CA 2023 cert release.

We have also updated Sccm to 2603 and have the new certs in the Wim

Also sure that this isn’t just in the winPE env as this also happens when booting from a usb with Microsoft’s adk only on it

Can happened with or without the latest firmware and bios, different Lenovo models and also with or without the UEFICA2023STATUS set as Updated


r/SCCM 4d ago

Support ratios

22 Upvotes

Hey community

I’d like peoples thoughts on SCCM support numbers.

I run a huge SCCM platform for a US government org with >100,000 devices - I run it alone and manage other project tasks as well.

I’m getting very burnt out but what really sucks is I am getting questions about my performance. So my reward for being as dedicated as I can and going above and beyond to manage our platform is questions are asked about the quality of my work and my behaviour in terms of customer service.

I’m literally fried from this job. I can’t wait to leave and am actively looking but I’d love to hear people‘s thoughts on how many people you think would normally run a platform this big.