Configuration Manager Desired Configuration Management ForumDiscussion on the Desired Configuration Management feature for System Center Configuration Manager© 2009 Microsoft Corporation. All rights reserved.Wed, 25 Nov 2009 13:35:18 Z135775df-eb75-495f-a9c4-b65c57bb6354http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/7d97f58e-eac4-4366-94ce-c704eb78139ehttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/7d97f58e-eac4-4366-94ce-c704eb78139eMicrosoft Galhttp://social.technet.microsoft.com/Profile/en-US/?user=Microsoft%20Galbuild OS configuration pack automaticallyHi, <br/> <br/> How could I build or create the OS configuration pack automatically? Is it possible to make use of Group Policy INF file to create the configuration pack? It's tedious task if modify the original configuration items 1 by 1 to my own settings.Wed, 18 Nov 2009 08:40:50 Z2009-11-25T13:27:55Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/363b9879-5617-4df8-b116-a25bad796669http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/363b9879-5617-4df8-b116-a25bad796669johndeshttp://social.technet.microsoft.com/Profile/en-US/?user=johndesCannot import configuration packs - Content schema validation failedHi,<br/><br/>I am having trouble importing oconfiguration packs into the DCM feature in SCCM SP2.<br/>The import configuration data wizard shows [Content schema validation failed]<br/>I'm trying to import the Microsoft Windows 2003 Config pack from Microsoft.<br/>I've tried from my PC and the actual central site server and receive the same error.<br/>The smsprov.log shows the following<br/><br/>[294][Wed 11/25/2009 09:37:49]:ERROR CSDMSource::InsertObject returned 12<br/>[294][Wed 11/25/2009 09:37:49]:<br/>*<br/>*<br/>e:\nts_sms_fre\sms\siteserver\sdk_provider\smsprov\sspconfigurationitem.cpp(1929) : The digest is not valid<br/>*<br/>*<br/>[294][Wed 11/25/2009 09:37:49]:<br/>*<br/>*<br/>The digest is not valid <br/>*<br/>*<br/><br/>If anyone has any ideas, please let me know...I've tried to find the error in the forums with no luck..<br/><br/>Many ThanWed, 25 Nov 2009 10:05:04 Z2009-11-25T13:35:18Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/e71707cc-1c92-4501-a4fd-bf078326452dhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/e71707cc-1c92-4501-a4fd-bf078326452dChrisTXhttp://social.technet.microsoft.com/Profile/en-US/?user=ChrisTXSDM and LAT files in the CCM\SDMAgent\TypeStore folder<p>Can anyone explain the purpose of these files? We have the DCM agent enabled, but have not yet caonfigured any templates. These files do not appear on all of our systems, but they do on some of our more closely monitored systems, and I need to explain what they are for.<br/><br/>Thanks in advance.</p>Tue, 24 Nov 2009 17:00:53 Z2009-11-24T17:00:53Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/04413c43-0aa2-4262-8752-270a09f89c13http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/04413c43-0aa2-4262-8752-270a09f89c13.Tim Harrisonhttp://social.technet.microsoft.com/Profile/en-US/?user=.Tim%20HarrisonWireless ConfigurationWould there be any way for me to use DCM (or any other SCCM feature) to report on my field laptops what machines have their wireless cards configured, what the SSIDs are and whether its a secured or unsecured wireless network?  We are getting reports of people in the field configuring their laptops - which transfer sensitive material - to connect to their unsecured home wireless routers and we'd like to know who is doing it so we can rectify the situation.<br/> <br/> ThanksWed, 18 Nov 2009 21:35:57 Z2009-11-23T23:20:26Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/5bfb4387-d022-4e29-a0bf-e6302b1d95e2http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/5bfb4387-d022-4e29-a0bf-e6302b1d95e2Microsoft Galhttp://social.technet.microsoft.com/Profile/en-US/?user=Microsoft%20GalSecurity Compliance Management Toolkit for Windows Server 2008 I found out that the Security Compliance Management Toolkit for Windows Server 2008 scripts for DCM CIs are not getting the correct value/actual value. Any face this problem as well? <br/>Mon, 23 Nov 2009 02:07:05 Z2009-11-23T23:20:44Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/41b42660-4946-47c4-b5d0-90836ca3bbf7http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/41b42660-4946-47c4-b5d0-90836ca3bbf7Wallyhttp://social.technet.microsoft.com/Profile/en-US/?user=WallySystem Center Configuration Manager 2007 Configuration Packs<p align=left><span lang=EN style="font-size:10pt;color:black;font-family:'Arial','sans-serif'">If you have questions or feedback about the <b>System Center Configuration Manager 2007 Configuration Packs</b> (published best practices for desired configuration management) e-mail </span><span style="font-size:10pt;color:black;font-family:'Arial','sans-serif'"><a title="mailto:cfgpacks@microsoft.com" href="mailto:cfgpacks@microsoft.com"><font color="#0000ff">cfgpacks@microsoft.com</font></a>.</span><span style="font-size:10pt;font-family:'Tahoma','sans-serif'"></span></p>Thu, 24 Apr 2008 00:13:15 Z2009-11-22T16:47:14Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/1049f16a-e17f-4d9b-9ee4-a5102d585d79http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/1049f16a-e17f-4d9b-9ee4-a5102d585d79AC76http://social.technet.microsoft.com/Profile/en-US/?user=AC76Multiple entries in the Object Tab of Configuration ItemI am recreating a number of internal compliance checks in SCCM that we currently carry out under SMS (setup using the Custom Update Publishing Tool (CUPT)).  <br/><br/>In one of these checks I check for a specific file name in one of two locations.  I can add this to the Object tab as two entries, 1 for each location, but the checks fails if it does not find it in both, which it won't.  I only want this to show as non-compliant if the file is in neither location.  This could be achieve in the CUPT with an OR statement.<br/><br/>Does anybody know if I can replicate this functionality in SCCM?<br/><br/>Does anyone have any experience with CP Studio, and does this allow more advanced CI's than can be configured directly in SCCM?<br/><br/>Thanks<br/>Andrew  <br/><br/>Thu, 05 Nov 2009 15:10:10 Z2009-11-20T12:14:34Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/63fdf8fe-bd3f-44e2-9a39-10274ce8403dhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/63fdf8fe-bd3f-44e2-9a39-10274ce8403dMicrosoft Galhttp://social.technet.microsoft.com/Profile/en-US/?user=Microsoft%20GalCompliance Status -- Not detectedHi, <br/><br/>I have no idea why all the CI item evaluation for compliance status is &quot;Not Detected&quot; in the report. Any Idea? Here's my DCMAgent.log. There is no error in the log. <br/><br/><br/><br/>DCMAgentJob({45CAB7FA-6D5A-4048-97FD-499CD5549ECE}): State - Detecting DCMAgent 13/11/2009 7:02:18 PM 5668 (0x1624)<br/>DCMAgentJob({45CAB7FA-6D5A-4048-97FD-499CD5549ECE}): ProcessDiscovery - Baseline - ScopeId_EDEFCFFF-53CD-437F-B16C-84DA40504545/ClonedCI_f4ddcf0b-aa00-4b5a-b1f9-bfa0145b7ba6 DCMAgent 13/11/2009 7:02:18 PM 5668 (0x1624)<br/>DCMAgentJob({45CAB7FA-6D5A-4048-97FD-499CD5549ECE}): ProcessDiscovery - Baseline - ScopeId_EDEFCFFF-53CD-437F-B16C-84DA40504545/ClonedCI_f4ddcf0b-aa00-4b5a-b1f9-bfa0145b7ba6 - Detecting ScopeId_EDEFCFFF-53CD-437F-B16C-84DA40504545/ClonedCI_f4ddcf0b-aa00-4b5a-b1f9-bfa0145b7ba6:4 DCMAgent 13/11/2009 7:02:18 PM 5668 (0x1624)<br/>DCMAgentJob({E16E242C-E707-4CB5-BD38-CB3B48986A50}): State - Reporting DCMAgent 13/11/2009 7:02:18 PM 5668 (0x1624)<br/>DCMAgentJob({E16E242C-E707-4CB5-BD38-CB3B48986A50}): ReportAssignmentState DCMAgent 13/11/2009 7:02:18 PM 5668 (0x1624)<br/>DCMAgentJob({E16E242C-E707-4CB5-BD38-CB3B48986A50}): State - Complete DCMAgent 13/11/2009 7:02:18 PM 5668 (0x1624)<br/>DCMAgentJob({45CAB7FA-6D5A-4048-97FD-499CD5549ECE}): CompleteCIDiscovery DCMAgent 13/11/2009 7:02:20 PM 1384 (0x0568)<br/>DCMAgentJob({45CAB7FA-6D5A-4048-97FD-499CD5549ECE}): CompleteCIDiscovery :: Baseline ScopeId_EDEFCFFF-53CD-437F-B16C-84DA40504545/ClonedCI_f4ddcf0b-aa00-4b5a-b1f9-bfa0145b7ba6 discovery succeeded DCMAgent 13/11/2009 7:02:20 PM 1384 (0x0568)<br/>DCMAgentJob({45CAB7FA-6D5A-4048-97FD-499CD5549ECE}):State - Reporting (scan) :: Baseline - ScopeId_EDEFCFFF-53CD-437F-B16C-84DA40504545/ClonedCI_f4ddcf0b-aa00-4b5a-b1f9-bfa0145b7ba6 - Compliant = False DCMAgent 13/11/2009 7:02:21 PM 1384 (0x0568)<br/>DCMAgentJob({45CAB7FA-6D5A-4048-97FD-499CD5549ECE}):State - Reporting (scan):: PartCIComplianceState - ScopeId_EDEFCFFF-53CD-437F-B16C-84DA40504545/BusinessPolicy_ba96ebcc-9fc7-4586-8231-ddb1e9eafc3e - Compliant = False Detected = True Applicable = True DCMAgent 13/11/2009 7:02:21 PM 1384 (0x0568)<br/>DCMAgentJob({45CAB7FA-6D5A-4048-97FD-499CD5549ECE}):State - Reporting (scan):: PartCIComplianceState - ScopeId_EDEFCFFF-53CD-437F-B16C-84DA40504545/ClonedCI_f78b6f53-d6eb-45a3-9617-95cf1d9418cf - Compliant = True Detected = False Applicable = True DCMAgent 13/11/2009 7:02:21 PM 1384 (0x0568)<br/>DCMAgentJob({45CAB7FA-6D5A-4048-97FD-499CD5549ECE}):State - Reporting (scan):: PartCIComplianceState - ScopeId_EDEFCFFF-53CD-437F-B16C-84DA40504545/ClonedCI_2c3e5cd7-5af7-4b6a-8895-7919f1d8eef2 - Compliant = True Detected = False Applicable = True DCMAgent 13/11/2009 7:02:21 PM 1384 (0x0568)<br/>DCMAgentJob({45CAB7FA-6D5A-4048-97FD-499CD5549ECE}):State - Reporting (scan):: PartCIComplianceState - ScopeId_EDEFCFFF-53CD-437F-B16C-84DA40504545/ClonedCI_ae849b37-ea4f-4d73-ba74-a1b8a27ff39c - Compliant = True Detected = False Applicable = True DCMAgent 13/11/2009 7:02:21 PM 1384 (0x0568)<br/>DCMAgentJob({45CAB7FA-6D5A-4048-97FD-499CD5549ECE}):State - Reporting (scan):: PartCIComplianceState - ScopeId_EDEFCFFF-53CD-437F-B16C-84DA40504545/ClonedCI_3fbe2ba7-d35a-4aa6-9f11-fc676038a17a - Compliant = True Detected = False Applicable = True DCMAgent 13/11/2009 7:02:21 PM 1384 (0x0568)<br/>DCMAgentJob({45CAB7FA-6D5A-4048-97FD-499CD5549ECE}):State - Reporting (scan):: PartCIComplianceState - ScopeId_EDEFCFFF-53CD-437F-B16C-84DA40504545/OperatingSystem_5a0dd2ae-f516-4ed7-aeb7-9c0f15af4520 - Compliant = True Detected = False Applicable = True DCMAgent 13/11/2009 7:02:21 PM 1384 (0x0568)<br/>DCMAgentJob({45CAB7FA-6D5A-4048-97FD-499CD5549ECE}): CompleteCIDiscovery :: 0 more Baseline CIs to be discovered. DCMAgent 13/11/2009 7:02:21 PM 1384 (0x0568)<br/>DCMAgentJob({45CAB7FA-6D5A-4048-97FD-499CD5549ECE}): CompleteCIDiscovery (all Baselines processed) - Released discovery semaphore DCMAgent 13/11/2009 7:02:21 PM 1384 (0x0568)<br/>DCMAgentJob({A453B4D3-CB95-4859-94FF-F624D64AA0F9}): State - Detecting DCMAgent 13/11/2009 7:02:21 PM 5668 (0x1624)<br/>DCMAgentJob({A453B4D3-CB95-4859-94FF-F624D64AA0F9}): ProcessDiscovery - Baseline - Microsoft.SolutionAccelerator.SecurityCompliance/Baseline_f4ba2e19-1278-49e1-b8ce-c4f839d0329c DCMAgent 13/11/2009 7:02:21 PM 5668 (0x1624)<br/>DCMAgentJob({A453B4D3-CB95-4859-94FF-F624D64AA0F9}): ProcessDiscovery - Baseline - Microsoft.SolutionAccelerator.SecurityCompliance/Baseline_f4ba2e19-1278-49e1-b8ce-c4f839d0329c - Detecting Microsoft.SolutionAccelerator.SecurityCompliance/Baseline_f4ba2e19-1278-49e1-b8ce-c4f839d0329c:3 DCMAgent 13/11/2009 7:02:21 PM 5668 (0x1624)<br/>DCMAgentJob({45CAB7FA-6D5A-4048-97FD-499CD5549ECE}): State - Reporting DCMAgent 13/11/2009 7:02:21 PM 5668 (0x1624)<br/>DCMAgentJob({45CAB7FA-6D5A-4048-97FD-499CD5549ECE}): ReportAssignmentState DCMAgent 13/11/2009 7:02:21 PM 5668 (0x1624)<br/>DCMAgentJob({45CAB7FA-6D5A-4048-97FD-499CD5549ECE}): State - Complete DCMAgent 13/11/2009 7:02:21 PM 5668 (0x1624)<br/>Fri, 13 Nov 2009 11:41:36 Z2009-11-18T17:21:46Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/bdf7f54f-dc3e-4622-9312-e5efe254bc35http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/bdf7f54f-dc3e-4622-9312-e5efe254bc35Schaijikhttp://social.technet.microsoft.com/Profile/en-US/?user=SchaijikIncompliancy due to standard firewall registry settingsThe setup we have now:<br/>SCCM 2007 SP2 with WS03-EC-Member-Server DCM configuration pack, we then created a policy based on the WS03-EC-Member-Server.inf, pushed it to the server OU and we now have compliant servers except for one CI.<br/><br/>Somehow the CI below is in error:<br/><br/> <table class=CI-details border=0> <tbody> <tr> <th>Name:</th> <td>WS03-EC-Member-Server-Standard Profile-Child</td> </tr> <tr> <th>Type:</th> <td>Operating System Configuration Item</td> </tr> <tr> <th>Content Version:</th> <td>3</td> </tr> <tr> <th>Actual Compliance State:</th> <td><span class=CI-details style="background-color:yellow">Non-Compliant</span></td> </tr> <tr> <th>Non-Compliance Severity:</th> <td style="font-variant:small-caps;color:red;font-weight:bold">Error</td> </tr> <tr> <th>Description:</th> <td>The standard profile CI contains the settings for Windows firewall policies that, allow the domain administrator to set firewall policies at the domain level.</td> </tr> </tbody> </table> The only way for me to get rid of this 'error' is to remove the following registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall<br/>even if I set this key to 1 (enabled) it still reports an incompliancy.<br/><br/>Could anyone explain the logic of this CI?<br/>Many thanks!Thu, 05 Nov 2009 16:28:42 Z2009-11-18T15:37:03Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/02d2f239-295c-43b2-9c9a-1af52aa82c05http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/02d2f239-295c-43b2-9c9a-1af52aa82c05Microsoft Galhttp://social.technet.microsoft.com/Profile/en-US/?user=Microsoft%20Gal"Account lockout threshold Script" CI detected the wrong valueHi, <br/> <br/> I am using WS08-EC-Domain-Account Lockout Policy-Parent, configuring &quot;Account lockout threshold Script&quot; CI.<br/> <br/> I have configured the validation to 5 instead of the default value 50. But I still can see from the parent CI, under the script still showing 50. And I realise it's actually assuming 50 is the current value/actual value. In this case, the CI detected/evaluated the wrong value. How could I change the value automatically from validation tab? <br/> <br/> WScript.Echo CheckRange(&quot;root\rsop\computer&quot;, &quot;RSOP_SecuritySettingNumeric&quot;, &quot;Setting&quot;, &quot;KeyName='LockoutBadCount' And precedence=1&quot;, &quot;50&quot;)<br/> Function CheckRange(wmiNamespace, wmiClass, wmiProperty, wmiWhere, ExpectedValue)<br/>  On Error Resume Next<br/>  Err.Clear<br/> <br/>  ' if &quot;50&quot; = &quot;No Key&quot;, CInt() will failed, set ExpectedValue = -1 in that case.<br/>  ExpectedValue = CInt(ExpectedValue)<br/>  If (Err.Number &amp;lt;&amp;gt; 0) Then<br/>   ExpectedValue = -1<br/>   Err.Clear<br/>  End If<br/>  'WScript.Echo &quot;ExpectedValue: &quot; &amp;amp; ExpectedValue<br/>  <br/>  Dim Compliant, NonCompliant, CurrentValue<br/> <br/>  ' Read Current value in this client<br/>  CurrentValue = GetCurrentValue(wmiNamespace, wmiClass, wmiProperty, wmiWhere)<br/>  'WScript.Echo &quot;CurrentValue: &quot; &amp;amp; CurrentValue<br/>  ' Case: Current Value = No Key<br/>  If (CurrentValue = &quot;&quot;) Then<br/>   'WScript.Echo &quot;CurrentValue: No Key&quot;<br/>   CheckRange = &quot;&quot;<br/>   Exit Function<br/>  End If<br/>  <br/>  CurrentValue = CInt(CurrentValue)<br/>  <br/>  ' set Compliant and NonCompliant return value<br/>  Compliant = ExpectedValue<br/>  NonCompliant = CurrentValue<br/> <br/>  ' Case: If ExpectedValue = 0, Means Unlimited, any value (CurrentValue) is Compliant<br/>     If (ExpectedValue = 0) Then<br/>   CheckRange = Compliant<br/>   Exit Function<br/>  End If<br/> <br/>  ' Case: If ExpectedValue &amp;lt;&amp;gt; 0, The CurrentValue should LessEqules Expected Value, that is Compliant<br/>  If (CurrentValue &amp;lt;= ExpectedValue) Then<br/>   CheckRange = Compliant<br/>   Exit Function<br/>     End If<br/>  <br/>  ' Other Case: NonCompliant<br/>  CheckRange = NonCompliant<br/>  <br/> End Function<br/> <br/> Function GetCurrentValue(wmiNamespace, wmiClass, wmiProperty, wmiWhere)<br/>  On Error Resume Next<br/>     Err.Clear<br/> <br/>     ' Get WMI data<br/>     Dim objWMIService, strWQL, objSettings, objInstance<br/>     Set objWMIService = GetObject(&quot;winmgmts:\\.\&quot; + wmiNamespace)<br/>     strWQL = &quot;Select &quot; + wmiProperty +&quot; from &quot; + wmiClass + &quot; where &quot; + wmiWhere<br/>     Set objSettings = objWMIService.ExecQuery(strWQL)<br/>     <br/>     For Each objInstance in objSettings <br/>   GetCurrentValue = objInstance.Setting<br/>   Exit For<br/>     Next<br/> <br/>  ' Case: No Key<br/>  If (Err.Number &amp;lt;&amp;gt; 0) Then<br/>   Err.Clear<br/>   GetCurrentValue = &quot;&quot;<br/>   Exit Function<br/>  End If<br/> End Function&lt;/ScriptBody&gt;<br/>Wed, 18 Nov 2009 08:37:25 Z2009-11-18T08:37:26Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/54d9ca5d-141a-4b7e-9a68-0288a45ebc1dhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/54d9ca5d-141a-4b7e-9a68-0288a45ebc1dRussell Wilemanhttp://social.technet.microsoft.com/Profile/en-US/?user=Russell%20Wilemanlsass.exe high CPU usage with desired configuration mgmt??Hi,<br/><br/>I've started to look at using desired configuration management (SCCM SP2) but noticed soon as I create a baseline and apply it to a collection the lsass.exe process ramps up leaving CPU at 80%+.<br/><br/>I dont 'think' it did this before SP2 but cant be sure. I tested the theory applying a baseline to a single PC and the CPU usgae shot up to abot 50%.<br/><br/>Any help appreciated!<br/><br/>Thanks<br/>Russell<hr class="sig">RMWTue, 17 Nov 2009 09:47:18 Z2009-11-18T09:21:12Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/7df34abd-3fce-4b54-92c5-a2d84a86f831http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/7df34abd-3fce-4b54-92c5-a2d84a86f831AC76http://social.technet.microsoft.com/Profile/en-US/?user=AC76XP clients not detecing updated baselines configurations for evaluationHi everyone, <br/><br/>Recently I have been setting up new configuration items and and assigning them via a few baselines to my test machines.  This has been working fine, my XP client has been picking up the updated baselines and I have been able to evaluate them.  Since couple of days ago i have not been able to get the client to pick up newer versions of the baslines (still picking up version 6 and 14 when they are at 8 and 16).<br/><br/>Has anybody come across this problem and know of a fix.  I have checked the DCM related log files on the client and nothing looks out of place.<br/><br/>Thanks<br/>Andrew  Fri, 13 Nov 2009 18:06:34 Z2009-11-23T21:06:06Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/82a98685-4c2b-4244-9b65-a5b56f5877e4http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/82a98685-4c2b-4244-9b65-a5b56f5877e4chrisharlowhttp://social.technet.microsoft.com/Profile/en-US/?user=chrisharlowVerify that a registry setting in HKLM is correctI'm still new to Desired Configuration Management.<br /><br />Basically, here is my problem. We had a virus run around our company. We've eliminated the virus, but there are some remnants that are preventing Automatic Updates from working on some machines. The virus changed several registry keys, so we need to find those systems and change the keys back.<br /><br />One if the damaged keys is:<br /><br />HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BITS\imagepath <br /><br />The value is supposed to be "%SystemRoot%\system32\svchost.exe -k netsvcs"<br />but the virus changed it to "%fystemRoot%\system32\svchost.exe -k netsvcs"<br /><br />I have a quick script to fix it, but I need to find the computers first. Does anyone know how to do this with DCM, or is there a better way?<br /><br />Thu, 08 Oct 2009 13:25:25 Z2009-11-23T19:13:02Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/8aae7724-3623-4244-a68d-383c9216803ehttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/8aae7724-3623-4244-a68d-383c9216803eAC76http://social.technet.microsoft.com/Profile/en-US/?user=AC76Reporting on DCM - Custom ReportHi, <br/><br/>I am just beginning to setup our reporting requirements in SCCM.  I have looked at some of the exisitng reports to see if I could make use of one of these as a base for this report.  <br/><br/>What I am trying to acheive is a list of all computers in a specific Collection, showing the number of Configuration Items assigned, compliant and non-compliant for a specific Baseline.<br/><br/>Any help would be appreciated.<br/>Thanks<br/>AndrewMon, 09 Nov 2009 12:49:28 Z2009-11-10T10:22:45Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/787eab62-950a-40cd-852c-d33ca2a466bdhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/787eab62-950a-40cd-852c-d33ca2a466bdMicrosoft Galhttp://social.technet.microsoft.com/Profile/en-US/?user=Microsoft%20GalDCM Configuration Items<p>Hi, <br/><br/>I am wondering why the Configuration Items of DCM Configuration Pack consists of 2 same rules but the configuration item names are different --&gt; child &amp; Parent. Please refer to the sample below. What is the purpose for this? <br/><br/>==&gt; WS08-EC-Domain-Account Lockout Policy-Child<br/>==&gt; WS08-EC-Domain-Account Lockout Policy-Parent<br/><br/><br/></p>Tue, 27 Oct 2009 10:05:31 Z2009-11-11T18:24:17Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/b4242a90-9bfc-4a05-a06a-5a7aa8f18315http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/b4242a90-9bfc-4a05-a06a-5a7aa8f18315k6497http://social.technet.microsoft.com/Profile/en-US/?user=k6497DCM validation that IIS Logging is enabled across WebSites on a webserverIn looking at the &quot;Vulnerability Assessment: IIS Logging Enabled&quot; configuration item from the Vulnerability Assessment pack, it appears that it only checks for logging compliance at the Web Sites node or level within the IIS Admin UI. It does not check the logging setting for the Default Web Site or any other webs defined.  Does anyone have a script that checks the settings for all webs?Wed, 04 Nov 2009 12:37:41 Z2009-11-11T18:24:53Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/1f772553-df56-408b-866b-f92f6dff6b50http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/1f772553-df56-408b-866b-f92f6dff6b50Vamsi Varma Ganarajuhttp://social.technet.microsoft.com/Profile/en-US/?user=Vamsi%20Varma%20GanarajuDCM Configuration Item for file or folder permissions<p>Hello<br /><br />I am creating a Configuration Item to&nbsp;Check permissions of a Folder on clients. In the Add "group or username" it only gives option for Domain\user.<br />Is there a way we could add Local administrator or other local accounts of clients. <br />Checked for similar questions but couldn't find any..<br /><br />Any pointers are appreciated. Thankyou !</p>Tue, 06 Oct 2009 17:25:05 Z2009-11-05T19:35:30Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/4707fa78-3bba-48d8-a4d9-2290320fe181http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/4707fa78-3bba-48d8-a4d9-2290320fe181jlozanhttp://social.technet.microsoft.com/Profile/en-US/?user=jlozanWMI Configuration SettingHello........I'm having some issues with a WMI check.  Here is how I have it setup:<br/> <br/> Namespace:   Root\cimv2<br/> Class:   NetworkAdapterConfiguration<br/> Property:   DefaultIPGateway<br/> Where Clause:   ServiceName - 'VMXNET'<br/> <br/> For Validation: Equals 192.168.21.3<br/> and I have &quot;report non-compliance event when this instance count fails&quot; checked.<br/> <br/> I created two just to test it with - one checking for the correct gateway and one without the correct gateway and they both show up as failed with &quot;instance count validation&quot; failures in the reports.  Does this basically mean that it couldn't find the WMI entry at all?  Normally when DCM finds something, but it has the wrong entry (like a reg check), it will report back to me what the value was - not just say &quot;instance count validation&quot;.<br/> <br/> Am I missing something?<br/> <br/> Here is a WMI entry that I have setup that IS working fine:<br/> <br/> Namespace:   Root\cimv2<br/> Class:    win32_service<br/> Property:   State<br/> Where clause:   name - 'CtxSecGwy'<br/> Validation:  Equals Running<br/> and &quot;report non compliance....&quot; is checked.Wed, 04 Nov 2009 18:44:46 Z2009-11-09T21:40:52Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/cd0798ef-c225-4992-a24e-ae6d31763e17http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/cd0798ef-c225-4992-a24e-ae6d31763e17EvanWPhttp://social.technet.microsoft.com/Profile/en-US/?user=EvanWPDCM CI for Registry KeyOk, I know this is probably something really easy and I'm just missing something so here it is. <br/><br/>I'm just looking for the presence of the <strong>HKLM\SYSTEM\CurrentControlSet\Control\Print\Connections</strong> key. I created a CI and a new Registry Object. <br/><br/>64-bit assiociation <strong>unchecked<br/></strong>Report a non-compliance event <strong>checked<br/></strong>Instance count Operator: <strong>Greater Than</strong><br/>Values: <strong>0</strong><br/>Severity: <strong>Information<br/></strong><br/>On my test machine I know the registry key exists and I'm still showing compliant. <br/><br/>What am I doing wrong? I know it's probably something simple. Thanks in advance. <br/>Mon, 02 Nov 2009 23:29:22 Z2009-11-09T23:59:50Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/7659f28d-1eda-4e6b-b8f0-c82aa10a7904http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/7659f28d-1eda-4e6b-b8f0-c82aa10a7904k6497http://social.technet.microsoft.com/Profile/en-US/?user=k6497Registry Permissions for LocalSystem in DCM<p>Could anyone provide the correct method to validate the permissions of the LocalSystem account to registry keys using the DCM registry object provided in the GUI?  The Domain\User works for domain accounts and the .\Administrators works for the local Administrators but .\LocalSystem, computername\LocalSystem, BUILTIN\LocalSystem do not seem to work for validating LocalSystem access.</p>Wed, 04 Nov 2009 11:35:02 Z2009-11-10T00:00:29Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/a208bf5c-511d-451c-9e9e-a14fef3d0868http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/a208bf5c-511d-451c-9e9e-a14fef3d0868The_Bootshttp://social.technet.microsoft.com/Profile/en-US/?user=The_BootsDCM: Detect presence of software that are not allowed<p>Hi everyone,</p> <p>I'm really noob with the DCM's section of SCCM but I've read a lot on forums and tried many things but I can't really find what I'm looking for.</p> <p>What I need is very simple. I want to create a list of Allowed softwares and I want to be able to check on a regular basis (monthly for example) which computers have softwares installed that are NOT in this list and what are those softwares.</p> <p>I understood that I need to create a configuration baseline but the only thing I can see in the CI wizard is how to check if a specific software is installed. The same thing on every forums that I've visited... people always ask about detecting if ONE software is installed or not but I'm looking for the oposite in fact.</p> <p>It seems to me that nor the Create Application Configuration Item neigther the Create General Configuration Item wizards would do the job.</p> <p>Does SCCM can do it ?<br/>Does DCM is the right tool into SCCM to do what I want or there is a better way ?<br/>How can I compare the already installed software list from the inventory to my allowed list ?</p> <p><br/>Thanks so much for your help.</p> <p>Alain</p>Thu, 27 Aug 2009 20:17:23 Z2009-11-04T09:27:36Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/605c5de4-9b5d-4b75-bc85-d0b465f3d48dhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/605c5de4-9b5d-4b75-bc85-d0b465f3d48dMicrosoft Galhttp://social.technet.microsoft.com/Profile/en-US/?user=Microsoft%20GalDCM - Access check failed against user 'domainaccount'Hi, After I evaluated, I click on View Report, I can see all configuration items also &quot;not detected&quot;. It's Windows Server 2008. In DCMAgent.log, it got this error &gt;&gt; Access check failed against user 'domainaccount'. CLR has been enabled on the Microsoft SQL Server.  What else I need to set?<br/><br/>Mon, 02 Nov 2009 04:33:29 Z2009-11-10T00:01:54Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/07008688-f875-40b4-a4a0-89206029a6dehttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/07008688-f875-40b4-a4a0-89206029a6dejlozanhttp://social.technet.microsoft.com/Profile/en-US/?user=jlozanChecking Folder Permissions with DCM - Local Groups/AccountsHello..I'm trying to use DCM to check permissions for folders across multiple servers.  It is fairly simple for a domain group with the object tab, but if I need to check local groups, I can't use the %computername% variable.  It gives me an error.  Obviously, I can't use the hostname of the box, because it will change depending on which server the dcm config item runs on.<br/> <br/> Ideas?  I've looked at hte xcalcs.vbs script, but I'm not quite sure how to incorporate that into checking for validation with DCM.<br/> <br/> Thanks in advance!Wed, 28 Oct 2009 14:44:04 Z2009-11-17T19:41:50Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/3659f76f-6f68-4188-b7c7-2dc461f65d40http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/3659f76f-6f68-4188-b7c7-2dc461f65d40Sherry Kissingerhttp://social.technet.microsoft.com/Profile/en-US/?user=Sherry%20KissingerDCMAgent.log - Access check failed aginst user 'id'<p align=left>On Server 08, from the Control Panel applet, when I ask for a refresh, I get the following in the DCMAgent.log:</p> <p align=left> </p> <p align=left>Access check failed against user 'domainaccount' </p> <p align=left> </p> <p align=left>domain account is the user id with Admin rights to the server, and full rights to every component of the console. I don't get that message for all Baseline/CIs.  I imported the System Center ConfigMgr Baselines &amp; those are evaluating fine on this 08 box.  But when I create my own General CI, it throws that error.  I recreated the steps on a different lab environment, and it worked fine; so I don't think it's my process; it has to be something I missed or misconfigured in this other lab.</p> <p align=left> </p> <p align=left>Any ideas on what that message means, and how to remediate?</p>Thu, 04 Sep 2008 15:27:03 Z2009-10-30T10:13:28Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/a56df736-bcbd-435e-8963-0055bb8fec2ehttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/a56df736-bcbd-435e-8963-0055bb8fec2ejlozanhttp://social.technet.microsoft.com/Profile/en-US/?user=jlozanUsing DCM to track GPO Compliance<p>I saw the other thread related to this, but the only solution I saw was in relation to using CP Studio - which we don't have.  Can someone tell me how to track a specific setting via WQL wmi query?  For instance, if I wanted to see if &quot;<strong>Administrative Templates\Windows Components\Terminal Services\Client/Server data redirection\Do not allow COM port redirection</strong>&quot; was enabled?</p> <p>Thanks - I've looked and looked and can't find anything.</p>Thu, 29 Oct 2009 19:18:23 Z2009-11-04T21:06:37Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/98e43cb6-c9ca-4172-a5f2-bc9fb0345da0http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/98e43cb6-c9ca-4172-a5f2-bc9fb0345da0Frank Vindignihttp://social.technet.microsoft.com/Profile/en-US/?user=Frank%20VindigniClient agent was successfully installed manually from the actual client itself but shows up in the Configuration Manager as no client agent was installedThe Client is a HP 7800 SSF with VPro enabled, running XP SP2 residing in the same domain as the site server, I manually ran the msi file from the XP client to install the SCCm client, the installation wizard stated the installation was successful but when looking at the XP collection I see the system but the client the columns for the site name and client installed shows nothing and no respectively.&nbsp; What am I doing wrong?Mon, 05 Oct 2009 19:29:36 Z2009-11-10T00:47:01Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/0e9123a1-160f-4eeb-8616-439df46882b3http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/0e9123a1-160f-4eeb-8616-439df46882b3momguyhttp://social.technet.microsoft.com/Profile/en-US/?user=momguyBPA conversion to DCMIt looks like at one point in time there was a tool (BPAtoDCM) to convert XML used by a best practice analyzer to a format the DCM could accept. I can't find any info on this tool - it is still available?Wed, 07 Oct 2009 16:32:20 Z2009-11-10T00:47:58Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/91f5ee86-16a1-4932-87c5-5e350654337bhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/91f5ee86-16a1-4932-87c5-5e350654337bxtiyu32nhttp://social.technet.microsoft.com/Profile/en-US/?user=xtiyu32nCheck if Registry Value Exists?I just want to simply validate if a registry value exists.  For example, everyone has the key HKLM\Software\Symantec\ABC\XYZ, but they should also have a string value in XYZ called &quot;XXX&quot;.  If that value does not exist (not blank, but NOT EXIST) then they are non-compliant.  I have tried to created this CI but it does not work.<br/><br/>Will this be an object or a setting?<br/><br/>If setting, how should it be configured?<br/><br/>Thanks!<hr class="sig">xtiyu32nMon, 28 Sep 2009 19:41:42 Z2009-10-06T18:33:59Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/eb5dd390-add5-4cea-8bb9-de26d2b2025ahttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/eb5dd390-add5-4cea-8bb9-de26d2b2025aPassBisshttp://social.technet.microsoft.com/Profile/en-US/?user=PassBissDCM Powershell Code SigningHi,<br /><br />I'm using powershell script in my CI's.<br /><br />I want to use my signed scripts in my CI's but it just doesn't work !!<br /><br />When I run the script outside DCM, everything fine.<br /><br />Does anyone knows if code signing is supported in DCM ?<br /><br />Allways get&nbsp;the&nbsp;Error Compliance state when I change the execution policy from unrestricted to allsigned.<br /><br />ThanksTue, 06 Oct 2009 13:35:02 Z2009-10-06T15:21:53Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/1ead2af7-4def-47a8-b52f-bf439e332288http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/1ead2af7-4def-47a8-b52f-bf439e332288PassBisshttp://social.technet.microsoft.com/Profile/en-US/?user=PassBissDCM Compliance Report problemHi !<br/><br/>As I get more baseline configured, I want to view report of compliance.<br/><br/>I try to run the report :  Summary compliance by configuration baseline<br/><br/>I get this error message:<br/> <ul> <li style="font-family:Verdana;font-size:8pt;font-weight:normal">An error has occurred during report processing. (rsProcessingAborted) <ul> <li style="font-family:Verdana;font-size:8pt;font-weight:normal">Query execution failed for data set 'DataSet0'. (rsErrorExecutingCommand) <ul> <li style="font-family:Verdana;font-size:8pt;font-weight:normal">For more information about this error navigate to the report server on the local server machine, or enable remote errors </li> </ul> </li> </ul> </li> </ul> Other report are working fine, like the Symmary compliance for a configuration item by computer.<br/><br/>Did any one got this message ?<br/><br/>ThanksTue, 29 Sep 2009 12:27:23 Z2009-09-29T12:27:23Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/15ab5472-115f-4c14-854a-8937df0f7708http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/15ab5472-115f-4c14-854a-8937df0f7708PassBisshttp://social.technet.microsoft.com/Profile/en-US/?user=PassBissMax caracter for username in folder permission CIs checkHi !<br/><br/>I tried to create a General CI that check the permissions on a folder.<br/><br/>When I try to enter my domain\goup name, DCM wont let me enter a group name that has more than 20 caracteres !?!?<br/><br/>Error message: &quot;The Windows Account name you entered is not valid. Please enter a user name of the form: Domain\User&quot;<br/><br/>I don't get any limitation for the length of the domain name !<br/><br/>Is this a bug or a limitation of DCM ?<br/><br/>Thanks !Tue, 22 Sep 2009 22:49:43 Z2009-09-28T21:45:55Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/3c05106b-73db-4ea0-831a-dc3721f66f02http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/3c05106b-73db-4ea0-831a-dc3721f66f02TonyMusorhttp://social.technet.microsoft.com/Profile/en-US/?user=TonyMusorFrequently updated applications and advice on how NOT to reset my baselineHello,<br/><br/>  I release new baselines and images every quarter worldwide. The image includes items like shockwave, flash, quicktime, etc. The release period is one month for ~2500 computers. During the one month period, if any updates for these products are released or zero days are released then they are slipstreamed into my deployment. <br/><br/>  My problem is updating the CI's to reflect these new versions, resets the baseline, and then I have to wait 1-3 days for evaluation to complete and all systems to report. This totally messes up my reporting, and I essentially lose two days of reporting any time a zero day is released. No too mention my heart sinks when my compliancy drops back down to zero again.<br/><br/>  I was thinking of creating the CI so it would look for the version number with a greater than or equal to. So that when the new version comes out, it will show up as compliant. Problem being most of my CI's reference the registry and versions in the registry are string based, so greater than or equal to is not an option. I will probably switch most of them to file versions to support this. <br/><br/>  How is everyone else dealing with their baselines and products that update very often? Do you put them into a seperate baseline or just reset the whole thing. I don't want to reset the baseline for the whole month if possible.<br/><br/> Thanks guys,<br/>        The Moose<br/><br/>Wed, 16 Sep 2009 23:17:38 Z2009-10-07T17:12:19Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/d582a362-90d7-45bb-9a18-f9ed47789dc5http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/d582a362-90d7-45bb-9a18-f9ed47789dc5xtiyu32nhttp://social.technet.microsoft.com/Profile/en-US/?user=xtiyu32nHKCU Registry Value?Is it not possible to configure a CI based on HKEY_CURRENT_USER?<br/><br/>I saw this post and that's what I assume this means?<br/><a href="http://social.technet.microsoft.com/forums/en-US/configmgrdcm/thread/a0410ceb-6ca5-47f4-97b8-9d3da78ea749/">http://social.technet.microsoft.com/forums/en-US/configmgrdcm/thread/a0410ceb-6ca5-47f4-97b8-9d3da78ea749/</a><br/><br/>I just want a simple CI that shows if the screen saver is enabled.  I have created one based on the HKCU\Control Panel\Desktop key and string value SCRNSAVE.EXE.  My screen saver is enabled, but it comes back non-compliant, showing that 3 other users are not compliant (mine is not listed).<br/><br/>BTW -- when I created a standard CI based on HKLM, it returns correctly.<br/><br/>Any ideas?  Thanks. <hr class=sig> xtiyu32nFri, 04 Sep 2009 19:43:56 Z2009-09-23T23:13:32Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/2eb443bc-c642-4b2e-be2e-eb63dac07e62http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/2eb443bc-c642-4b2e-be2e-eb63dac07e62TonyMusorhttp://social.technet.microsoft.com/Profile/en-US/?user=TonyMusorPrinting DCM CI's and Baseline'sHello,<br/><br/>  I was wondering what everyone uses to print and review their configuration items and baselines? I came across the article &quot;print your task sequence automagically&quot; and love this for task sequences. Unfortunately I couldn't get it to work on my CI's or Baseline's and am not too familiar with XML stuff. <br/><br/>  Does anyone have any recommendations on how to print the CI's and baseline's into an easily reviewable format? I have alot of settings being checked wthin each CI and want to review those with my team.<br/><br/> Thank you,<br/>      The Moose<br/> Wed, 16 Sep 2009 23:08:13 Z2009-09-28T21:47:28Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/605a4109-c11d-448d-ade9-41eaf3e48435http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/605a4109-c11d-448d-ade9-41eaf3e48435Brad-Chttp://social.technet.microsoft.com/Profile/en-US/?user=Brad-CMAXPWAGEHi All,<br/><br/>  Do you know how to check items such as MAXPWAGE using Desired Configuration Manager?  There is no registry setting for this configuration item.Wed, 16 Sep 2009 06:51:41 Z2009-09-16T17:28:58Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/db8880b5-bcd3-4fc0-beb6-6f32105ae7c2http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/db8880b5-bcd3-4fc0-beb6-6f32105ae7c2SYLVESTERCLARKhttp://social.technet.microsoft.com/Profile/en-US/?user=SYLVESTERCLARKCI Agent Failed to Startupi imported ConfigManager2007 configuration pack into SCCM 2007 and applied to server collections containing AD and SCCM machine. after a while, running HomePage Summarization, the graph shows 100% Unknown state. furthermore, in c:\program files\SMS_CCM\ciagent.log opened using SMSTrace, it shows error that <strong>CI Agent Failed to Startup (0x800004015). </strong> <br/> I have verified that SCCM has .Net FrameWork 2.0 installed. Logged on account is Ent. Admin.  <br/> what exactly is causing this issue.<br/> <br/>Mon, 07 Sep 2009 09:50:07 Z2009-10-08T16:38:43Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/8bc5968b-171e-4935-bb28-da061da78416http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/8bc5968b-171e-4935-bb28-da061da78416Brad-Chttp://social.technet.microsoft.com/Profile/en-US/?user=Brad-CCustom Configuration Packshey Everyone,<br/><br/>  is there a tool to automate the creation of configuration packs?  Can I baseline a machine (e.g. Vista / Win7) and have its settings output as a configuration pack?  or, Can I start with a bunch of registry files or an rsop and turn them into a configuration pack?<br/><br/>  In other words, how can I create my configuration baseline without having to set each setting one at a time?Mon, 14 Sep 2009 05:37:27 Z2009-09-14T16:46:43Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/377f4eb0-ff42-46d1-8f19-3fc83b70d01bhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/377f4eb0-ff42-46d1-8f19-3fc83b70d01bDana Daughertyhttp://social.technet.microsoft.com/Profile/en-US/?user=Dana%20DaughertyPowershell Scripts Cause DCM Discovery Failure/Errors on Some ServersIs anyone having problems with using Powershell scripts in DCM validation rules? I am targeting about 1500 servers with about 200 validation rules. 37 servers have discovery failures only on the validation rules that use Powershell scripts. The scripts work fine on the remaining 1400+ servers. The problem servers are Windows 2003/Windows 2008. Something the servers have in common is that nearly all of them are Citrix or Virutual servers. Attached is a snippet of discovery.log for one problem server:<br/> <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function expand('%systemroot%\system32\windowspowershell\v1.0'): Object count final: 1. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function alternateWowUapFileNames('C:\WINDOWS\system32\windowspowershell\v1.0','','Native','FileUserAccountLimited'): Object count final: 0. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function alternateWowFileName('C:\WINDOWS\system32\windowspowershell\v1.0','FileWow6432File'): Object count final: 1. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function alternateWowUapFileNames('C:\WINDOWS\system32\windowspowershell\v1.0','','FileWow6432File','FileUserAccountLimited'): Object count final: 0. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function none(): The interoperation method 'OpenProcessToken' returned Win32 error '0x000003F0(1008)' message ''. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function none(): The interoperation method 'OpenProcessToken' returned Win32 error '0x000003F0(1008)' message ''. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function directoryExists('C:\WINDOWS\system32\windowspowershell\v1.0'): Object count final: 1. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function none(): The interoperation method 'OpenProcessToken' returned Win32 error '0x000003F0(1008)' message ''. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function none(): The interoperation method 'OpenProcessToken' returned Win32 error '0x000003F0(1008)' message ''. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function files('C:\WINDOWS\system32\windowspowershell\v1.0','powershell.exe',''): Object count final: 1. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function none(): The interoperation method 'OpenProcessToken' returned Win32 error '0x000003F0(1008)' message ''. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function none(): The interoperation method 'OpenProcessToken' returned Win32 error '0x000003F0(1008)' message ''. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function time('C:\WINDOWS\system32\windowspowershell\v1.0\powershell.exe','c'): Object count final: 1. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function none(): The interoperation method 'OpenProcessToken' returned Win32 error '0x000003F0(1008)' message ''. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function none(): The interoperation method 'OpenProcessToken' returned Win32 error '0x000003F0(1008)' message ''. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function time('C:\WINDOWS\system32\windowspowershell\v1.0\powershell.exe','w'): Object count final: 1. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function none(): The interoperation method 'OpenProcessToken' returned Win32 error '0x000003F0(1008)' message ''. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function none(): The interoperation method 'OpenProcessToken' returned Win32 error '0x000003F0(1008)' message ''. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function fileAttributes('C:\WINDOWS\system32\windowspowershell\v1.0\powershell.exe'): Object count final: 1. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function none(): The interoperation method 'OpenProcessToken' returned Win32 error '0x000003F0(1008)' message ''. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function none(): The interoperation method 'OpenProcessToken' returned Win32 error '0x000003F0(1008)' message ''. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function fileSize('C:\WINDOWS\system32\windowspowershell\v1.0\powershell.exe'): Object count final: 1. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function none(): The interoperation method 'OpenProcessToken' returned Win32 error '0x000003F0(1008)' message ''. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function none(): The interoperation method 'OpenProcessToken' returned Win32 error '0x000003F0(1008)' message ''. <br/> 6/15/2009 8:22:36 AM    DiscoveryProvider:Discovery Function fileVersionInfo('C:\WINDOWS\system32\windowspowershell\v1.0\powershell.exe'): Object count final: 1. <br/> <br/> 6/15/2009 8:22:37 AM    DiscoveryProvider:Discovery Function execute('#Script gets the execution policy setting.<br/>                                                                         $ErrorActionPreference = 'SilentlyContinue'<br/>     $ExPol = (Get-ExecutionPolicy)<br/>     <br/>             <br/>     If (($ExPol -like &quot;RemoteSigned&quot;) -or ($ExPol -like &quot;Un','ps1',''): The provider encountered an error condition during function execution. <br/> <br/> I realize the interopeation errors are considered to be bogus. The final line of the snippet seems to be the issue. The other 1400+ servers do process the script without issue. Anyone have some input on this? Seems like a bug......Mon, 15 Jun 2009 06:21:22 Z2009-09-07T05:58:27Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/496e0c25-1ac1-465a-8cf6-ab65aa809a62http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/496e0c25-1ac1-465a-8cf6-ab65aa809a62Marco Weisshttp://social.technet.microsoft.com/Profile/en-US/?user=Marco%20WeissSCCM with SMS 2003 AD Ext.Hi Guys,<br/> <br/> i have installed a SCCM environment and it works pretty well, so far. But now i have the problem, that clients do work correctly with the sccm. i configured the Client Push Installation as followed: MSI PROPERTIES are  INSTALL=&quot;ALL&quot; SMSSITECODE=&quot;xxx&quot; SMSCACHESIZE=&quot;20480&quot; SMSSLP=&quot;FQDN Name from Server&quot; CCMHTTPPORT=&quot;80&quot; CCMHTTPSPORT=&quot;443&quot; CCMHTTPSSTATE=&quot;0&quot; CCMFIRSTCERT=&quot;0&quot; <br/> <br/> Clients receives the advertisements normaly, but then they stay in status &quot;Downloading&quot; for ever... :-(<br/> Do you have some ideas?<br/> <br/> The SCCM is installed without SCCM 2007 AD Extend, but we have a SMS 2003 Schema Extension. <br/> And a second Question: There is a second SMS 2003 Infrastruture in this Domain. Can this create any Problems?<br/> <br/> Very best Regards,<br/> MarcoTue, 01 Sep 2009 14:16:59 Z2009-09-14T16:49:25Zhttp://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/72e6be38-1274-44ce-8b2e-502e46125b09http://social.technet.microsoft.com/Forums/en-US/configmgrdcm/thread/72e6be38-1274-44ce-8b2e-502e46125b09RK Jeevanhttp://social.technet.microsoft.com/Profile/en-US/?user=RK%20JeevanDCM- Something strange.Hi All. We have configured a Baseline for checking if &quot;user logged into the machine&quot; (domain account) has the Standard Wall paper and Screen saver which is defined in the Group policy.  When checked the DCM report, it show as non-complaint even though the valid Wall paper and screen save is available for the user. When checked further, its actually comparing the value of WP and SV set in the Baseline with all user profiles available in the system registry including local user accounts.  How to mitigate this. We want it should check the baseline value against logged on user only (domain account) and not with local user profiles.<br/><br/>Thank YOu.Wed, 12 Aug 2009 14:56:46 Z2009-08-26T20:49:07Z