MECM - reoccurring patching issue

8 views
Skip to first unread message

Heaton, Joseph@Wildlife

unread,
Feb 17, 2022, 11:34:18 AM2/17/22
to ntsyste...@googlegroups.com

My MECM environment is completely on-prem.  I am not integrated with Intune at all, at least not for patching.  On the desktop side, we don’t have more than a handful of test machines in Intune.  We use Intune for all of our phones.  On the server side, I don’t have any in Intune.  So, I’m patching my Azure servers with my on-prem MECM.  Some of the servers patch great, no problems.  But, I do have a couple of trouble machines that give me fits pretty much every month.  I look in the WUAHandler.log, and I see a scan done around the time I would expect, for it to find and download the patches, but it doesn’t indicate that it saw the updates.  A bit later, it does see Security Intelligence Update for Microsoft Defender, so I know that it is connecting, and seeing things it needs, but for some reason, it is not seeing the monthly patches.  However, in ccmcache, I do see folders being created, and then sitting empty.  I’m also not seeing anything in the Updateshandler.log.  What else can I look at to figure out why this machine is not seeing and downloading the patches?

 

Joe Heaton

Managed Services and Operational Support Unit

Information Technology Operations Branch

Data and Technology Division

CA Department of Fish and Wildlife

1700 9th Street, 3rd Floor

Sacramento, CA  95811

Desk:  916-919-5816

 

Michael B. Smith

unread,
Feb 17, 2022, 12:04:59 PM2/17/22
to ntsyste...@googlegroups.com

Verify the system is in the proper collection?

 

Reinstall CCM agent?

--
You received this message because you are subscribed to the Google Groups "ntsystemcenter" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntsystemcente...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsystemcenter/SJ0PR09MB6686C98EAA9A774EFDBDF39AAA369%40SJ0PR09MB6686.namprd09.prod.outlook.com.

CESAR. A

unread,
Feb 18, 2022, 6:24:56 PM2/18/22
to ntsyste...@googlegroups.com
You can't patch servers with Intune so that's out. 

You can use update management in a automation account with logs analytics and keep everything private with AMPLS. Install the Mon agent with Azure policies and create patch schedule. I just configured everything for a client. Schedule is similar to SCCM and cam be integrated for groups. 

Cesar A

Reply all
Reply to author
Forward
0 new messages