Ask a questionAsk a question
 

AnswerClients going into unmanaged mode

  • Monday, November 02, 2009 8:55 PMMGMNVA Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     

    Is there a document that describes the rules that forefront uses to put machines into the pending actions group with a pending action of "uninstall agent". I am trying to figure out the details of what this means.

Answers

  • Tuesday, November 03, 2009 3:36 PMKurt FaldeMSFT, ModeratorUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Answer
    The main 2 reasons for computers going into pending  uninstall are

    1. Discovery rule was deleted for that system somehow.
    2. Computer account no longer exists in AD (ie you do pruning of accounts in AD and this one was removed recently possibly)
    CSS Security Support Engineer (FCS/MBSA/WUA/Incident Response) Check out my blog http://blogs.technet.com/kfalde

All Replies

  • Tuesday, November 03, 2009 2:06 AMNick Gu - MSFTMSFT, ModeratorUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     

    Hi,

     

    Thank you for your post.

     

    As far as I know, MOM uses discovery rules to determine what the “desired” state of an agent is. When machines are deployed via the install/uninstall wizard or approved manually via Pending Actions a corresponding discovery rules is created for the machine with a desired state of Agent-managed. And FCS has a auto-approval feature where is hourly queries for manual installations and approves them. For some reason, the discovery cycle MOM thinks that you have deleted the discovery rule and no longer wish the computer to be agent managed. If the MOM servers action account is an admin on the client machine it will try to uninstall the agent on your behalf. If it is not, it will place the computer in Pending Actions with an action for uninstall.

     

    Regards,


    Nick Gu - MSFT
  • Tuesday, November 03, 2009 3:36 PMKurt FaldeMSFT, ModeratorUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Answer
    The main 2 reasons for computers going into pending  uninstall are

    1. Discovery rule was deleted for that system somehow.
    2. Computer account no longer exists in AD (ie you do pruning of accounts in AD and this one was removed recently possibly)
    CSS Security Support Engineer (FCS/MBSA/WUA/Incident Response) Check out my blog http://blogs.technet.com/kfalde
  • Friday, November 06, 2009 9:46 PMMGMNVA Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     
    Kurt,

     That answer helps a great deal. Is there an automated cleanup process to deal with these deleted accounts? I am looking at hundreds both comming and going.