Hi
I have about 1500 SCCM OSD deployed machines. Those 1500 are made up of 16 Dell models and 26 HP models and only the DELL OptiPlex 755 models experience this issue.
Randomly the machine will hang, we are not sure what triggers it but there is always this event log message before the hang occurs:
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10016
Date: 22/05/2009
Time: 1:16:56 PM
User: NT AUTHORITY\SYSTEM
Computer: [Computer Name]
Description:
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
{24FF4FDC-1D9F-4195-8C79-0DA39248FF48}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18). This security permission can be modified using the Component Services administrative tool.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
The CLSID is Quarantine Private SHA Binding class which appears to be related to NAP.
Out environment is as follows:
Desktop OS is XP SP3
Single SCCM 2007 server
SCCM Server OS is Windows 2003 SP2 R2
Single Mixed Mode Site
Not using NAP
We have tried replacing drivers on the machines but this does not help and the DCOM event log message always pre-ceeds a crash, after which we have to power cycle the machine to get it back up. We also apply 99% of the Enterprise Client policies from the Windows XP Security Guide if that helps.