Tuesday, February 17, 2015

ConfigMgr 2012 Client Install Errors

There are a number of reasons why the ConfigMgr client fails to install… permissions, WMI, environment variables, certificate errors etc. So this post is going to be a collection of the random installation errors that I have come across in my time and how they were resolved. As news ones are identified I will add to this post.

Symptom:
  • Client installs successfully (%WinDir%\ccmsetup\Logs\ccmsetup.log)
  • Software Center is blank (Client reinstall)
  • On a new client install the logs directory (%WinDir%\CCM\Logs) is mostly empty
  • Errors can be found in both the CertificateMaintenance.log and ClientIDManagerStartup.log
CertificateMaintenance.log

Crypt acquire context failed with 0x8009000f.
CCMDoCertificateMaintenance() failed (0x8009000f).
CCMDoCertificateMaintenance() failed (0x8009000f).
Raising pending event:
instance of CCM_ServiceHost_CertificateOperationsFailure
{
DateTime = "20140909183201.373000+000";
HRESULT = "0x8009000f";
ProcessID = 5080;
ThreadID = 4824;
};
CCMDoCertificateMaintenance() raised CCM_ServiceHost_CertificateOperationsFailure status event.

ClientIDManagerStartup.log

RegTask: Failed to get certificate. Error: 0x80004005

Resolution:
  • On the client open the Services MMC snap-in and stop the SMS Agent Host service
  • Navigate to C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys
  • Locate the crypto file starting with “19c5cf”
  • Backup the file to a temporary directory and then delete it
  • Restart the SMS Agent Host service
  • The client should recreate the crypto file starting with “19c5cf” and the go through the registration process
Symptom:
  • Client install fails with error code 0x80004004 (%WinDir%\ccmsetup\Logs\ccmsetup.log)
  • MSI error code 1789 referenced in the client.msi.log (%WinDir%\ccmsetup\Logs\client.msi.log)
ccmsetup.log

MSI: Setup failed due to unexpected circumstances
The error code is 800706FD
CcmSetup failed with error code 0x80004004

client.msi.log

ERROR: Failed to resolve the account <Domain\Account> (1789)

Resolution:
  • On the client open the Services MMC snap-in and ensure that the Netlogon service is set to Automatic and it is running
  • Open regedit and navigate to HKLM\Software\Microsoft\
  • Delete the ccmsetup key
  • Reboot the machine
  • Reinstall the client
Symptom:
  • Client fails to install with the Couldn’t find an MP source through AD. Error 0x80004005 (%WinDir%\ccmsetup\Logs\ccmsetup.log)
ccmsetup.log

Failed to get assigned site from AD. Error 0x80004005
GetADInstallParams failed with 0x80004005
No valid source or MP locations could be identified to download content from. Ccmsetup.exe cannot continue
Couldn't find an MP source through AD. Error 0x80004005

Resolution:
  • Ensure that your boundaries and boundary groups in ConfigMgr are setup appropriately
  • On the client ensure that the Netlogon service is running and set to Automatic
  • Ensure the client is communicating with the domain properly
  • Reinstall the client
Symptoms:
  • Client installation fails with error code 1603 (%WinDir%\ccmsetup\Logs\ccmsetup.log)
ccmsetup.log

MSI: Could not access network location %APPDATA%
File %WinDir%\ccmsetup\<GUID>\client.msi installation failed. Error text: ExitCode 1603
Action: CostFinalize
ErrorMessages:
Could not access network location %APPDATA%\.

Resolution:
  • Open regedit and navigate to HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
  • Change the value for %APPDATA% to %USERPROFILE%\AppData\Roaming
  • Reinstall the client (Reboot may be required)
Source found here.

Symptom:
  • The client installs successfully however it will not report into it’s management point
  • Registration errors can be found in the ClientIDManagerStartup.log
  • Client does not show up as having an active client installed in the ConfigMgr client
ClientIDManagerStartup.log

<![LOG[RegTask: Failed to get certificate. Error: 0x80004005]LOG]!><time="<Time>" date="<Date>" component="ClientIDManagerStartup" context="" type="3" thread="5972" file="regtask.cpp:615">

Resolution:
  • Backup all files in the C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys folder for Windows 7 or C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys folder for Server 2003
  • Remove the (19c5cf9c7b5dc9de3e548adb70398402_ac168ff2-23d3-4a00-bd1d-dd27ff040362) folder
  • Restart the SMS Agent Host Service to recreate these certificates
  • Client should now register and start pulling down policies
Symptom:
  • Client fails to install with error code 80041002 (%WinDir%\ccmsetup\Logs\ccmsetup.log)
ccmsetup.log

MSI: Setup was unable to compile the file DiscoveryStatus.mof
CcmSetup failed with the error code 80041002

Resolution:
  • Open an administrative CMD prompt
  • Navigate to C:\Program Files\Microsoft Policy Platform
  • run the following command mofcomp ExtendedStatus.mof
  • Reinstall the client

Monday, February 16, 2015

Microsoft System Center 2012 Configuration Manager Servicing Extension


In December the Configuration Manager Sustained Engineering team officially released their Servicing Extension. This add-on helps administrators keep track of things like the release of new hotfixes and cumulative updates, lists the sites you manage and the current version they are running, a client targeting node that enables you to create queries for rolling out updates to machines and a blogs node that brings the latest updates from Microsoft’s official ConfigMgr blogs all from within the console.

Simply download the add-on from here and install it on a machine which has the ConfigMgr console installed. Once installed, open the ConfigMgr console and then open the Administration workspace and you will now see the Site Servicing node. Expand Site Serving and you will have the following nodes listed – Releases, Site Versions, Client Targeting and Blogs.




Site Servicing – The Site Servicing node displays a summary of the latest updates that have been released, the most recent blog posts from the System Center Configuration Manager Team blog as well as the The Official Configuration Manager Support Team blog as well give you the ability to configure proxy settings as well as display the current version of the Servicing Extension add-on installed.

Releases – The Release node displays a list of updates that have been published for ConfigMgr. You can list all updates or filter between ones specifically for SP1 or R2. Each release entry includes links for the KB article, the URL to download the update plus an option to create a query for the update. (For example to identify all clients missing the update) You can also mark an update or all update entries as Read. 

Site Versions – The Site Versions node will list all sites in your hierarchy and information like server name, site code, site name, base version and cumulative update installed.

Client Targeting – The Client Targeting node allows you to create queries to be used to identify clients for deploying updates.

Blogs – The Blogs node will automatically update as new updates are posted to Microsoft’s officially ConfigMgr blogs. Currently you can filter articles from the System Center Configuration Manager Team Blog and The Official Configuration Manager Support Team Blog. You also have the ability to mark articles as Read.

Overall I think this add-on and the information it provides is a great idea and I hope that this is something that Microsoft will integrate into the product for future releases.

Wednesday, February 11, 2015

Software Center returned error code 0x0041013 (-2147217389)

I've come across this issue a couple of times after upgrading the ConfigMgr client from 2007 (4.x) to 2012 (5.x) where Software Center will never open successfully and present a the user's applications. The 2012 client will install and seems to start communicating successfully however when a user goes to open Software Center they are presented with the following error:

Software Center cannot get the current status for some of the software. Software Center will list any items with available status. You can press F5 to refresh the view. If the problem persists, contact your help desk.

If you expand the More Information section you get the following error code:

Loading Software Center returned error code 0x0041013 (-2147217389).

No matter how long you leave the client, refresh policies or even after a reinstall the problem persists. After much searching online I finally found a post that referenced the same error code and how to resolve the problem. (My next step was a call to Microsoft so it saved me a bunch of time when I found it) Essentially the problem  stems from the 2007 client failing to uninstall cleanly leaving behind possibly two registry keys that can cause the issue. Check the following:
  • Open regedit
  • Navigate to HKEY_CLASSES_ROOT\CLSID\{555B0C3E-41BB-4B8A-A8AE-8A9BEE761BDF}\InProcServer32
  • Ensure that the default value is set to C:\WINDOWS\CCM\ccmcisdk.dll
  • Navigate to HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{555B0C3E-41BB-4B8A-A8AE-8A9BEE761BDF}\InProcServer32
  • Ensure that the default value is blank (If not delete the value)
  • Open the ConfigMgr client applet and kick off a policy refresh action
  • Give it a few minutes (You can monitor the PolicyAgent.log file on the client)
  • Once the policy refresh is complete open Software Center and the user should new be presented with their applications

Sunday, February 8, 2015

SMS Migration Manager Stops Unexpectedly


Recently I was reviewing site server health in the Monitoring workspace in the ConfigMgr console and I came across the following error that a couple of site servers were reporting pretty consistently. The SMS_Migration_Manager component for each server was reporting the following message:

SMS Executive detected that this component stopped unexpectedly.
Possible cause: The component is experiencing a severe problem that caused it to stop unexpectedly.
Solution: Refer to your ConfigMgr Documentation or the Microsoft Knowledge Base for further troubleshooting information.


On the site server itself you will find the same errors listed in the Application event log and when reviewing the migmctrl.log file (<Install Location>\Microsoft Configuration Manager\Logs) you will see the following:

MigMCtrI: FAILED to CREATE JobManager instance, error = The parameter is incorrect., 80070057
MigMCtrI: FAILED to START WorkltemMgr. error = The parameter is incorrect., 80070057
MigMCtrI: FAILED to INITIALIZE, error = The parameter is incorrect,, 80070057


After some searching online I across this post which outlined the issue and provided information on how to resolve it.
  • Browse to <Install Location>\Microsoft Configuration Manager\bin\X64
  • Copy microsoft.configurationmanagement.migrationmanager.dll to a temp folder
  • Browse to that site's parent a copy microsoft.configurationmanagement.migrationmanager.dll to the server and overwrite the original file
  • Open an administrative cmd prompt and navigate to C:\Windows\Microsoft.NET\Framework64\v4.0.30319
  • Run the following:  
 regasm.exe <ConfigMgr Installation Directory>\bin\X64\microsoft.configurationmanagement.migrationmanager.dll /codebase
    • You should get the following message in the cmd window
                         Types registered successfully


      • Open services.msc and restart the SMS_Executive service

      Monitor the migmctrl.log file and wait for the following entries:

      MigMCtrI: the workitem queue is full!
      MigMCtrI: WAIT 3 event(s) For 60 minute(s) and 0 second(s).


      Give the server about an hour and check the log to ensure the errors have gone away. All migration jobs had been long completed and I only had this issue happen on a few secondary sites. I still have not found a root cause for this issue and it has yet to occur again.

      Friday, February 6, 2015

      Automatic Deployment Rule Fails to Download content

      I currently use a Automatic Deployment Rule (ADR) for deploying System Center Endpoint Protection definition updates. Setting up an ADR is pretty straight forward however I was seeing the following error in the ruleengine.log file (Located at <ConfigMgr Installation Directory>\Logs)

      Downloading content with ID <Unique Content ID> in the package
      Failed to download the update from internet. Error = 1326
      Failed to download ContentID <Unique Content ID> for UpdateID <Unique Update ID>. Error code = 1326


      There are a few things that you need to be aware of when setting up a ADR:
      • The ADR will run in the SYSTEM context
      • If a proxy server is in use for internet access ensure that rules are setup appropriately for your site server
      • Ensure that the permissions for the file share (Full) and source directory (Modify) are setup appropriately. If your source directory is located on a different server the computer account of your site server will need modify access to the package source directory
      • The ADR will use the UNC path to access the share even when the directory is local to that site server
      For my setup everything checked out. The site server and the package source were located on the same server so permissions weren't the issue. Proxy server rules were already setup to allow the site server to download the required content for specific sites. I double checked and verified that the site server was indeed able to connect to the URL required yet the problem persisted. This server had been recently upgraded to Server 2012 R2 and I was connecting to it using a CNAME so what I found was that when I was logged onto the server and then browsed to the share using the UNC path (Using a CNAME in place of the server name) I was prompted for credentials. So when the ADR would run it would fail at the point where it tried to access the share for the package source path. With Server 2008 R2 disabling strict name would resolve this problem however with Server 2012 R2 you need to disable loopback checking.
      • Open Regedit.exe
      • Navigate to HKLM\SYSTEM\CurrentControlSet\Control\Lsa
      • Create a new DWORD value called "DisableLoopbackCheck"
      • Set the value to “1”
      • Test by connecting to the UNC path using your CNAME (If you are still being prompted reboot your server)
      Once loopback checking was disabled the ADR ran without issue.

      Friday, January 2, 2015

      Resetting BITS Jobs

      There have been instances where Configuration Manager distribution points stop accepting content. Network services are fine and I can copy the content manually but it will never get there on its own.  I've only had this happen a couple of times on Server 2008 R2 machines. The only role installed on these servers is a distribution point and there are no shared services on the box. What seems to happen is that the BITS client gets stuck on a job and all other jobs get queued indefinitely. Since BITS is a component of Windows Configuration Manager never reports a problem. The only symptom is that content never gets there. Here is how you can check the status of BITS jobs.

      ·         Launch administrative PowerShell
      ·         Run Import-Module BitsTransfer
      ·         Run Get-BitsTransfer -AllUsers
      ·         Open Task Scheduler and create a new task (Note for Windows 8 or Server 2012 and above you need to use Sysinternals PsExec with the -s switch (http://msdn.microsoft.com/en-us/library/bb897553.aspx)
      ·         Open Task Scheduler
      §  Right-click Task Scheduler (Local) and select Create Task
      §  Give the task a name - Rest BITS Jobs
      §  Under Security options Change the user to the local SYSTEM account
      §  Enable Run with highest privileges
      §  On the Actions tab select New...
      §  Set up the new Action
      §  Action -Start a Program
      §  Program browse to C:\Windows\System32\bitsadmin.exe
      §  Add arguments /reset /allusers
      §  Click OK
      §  On the Settings tab ensure the Allow task to be run on demand option is enabled
      ·         Run the task
      ·         Give the task a couple of minutes to run
      ·         Go back to PowerShell and run Get-BitsTransfer -AllUsers
      ·         There should now jobs listed in the queue
      ·         Delete the task from Task Scheduler

      Saturday, February 2, 2013

      Poor Video Performance in vsphere 4.1 remote console after Xendesktop VDA is installed


      When you build a Windows 7 XenDesktop image that is hosted on VMware vSphere 4.1 you will find that your gold image will perform as it should when using vSphere's remote console feature until you install the XenDesktop Virtual Desktop Agent (VDA). After the VDA is installed, your remote console session has poor video performance. On top of that when you launch a XenDesktop session using your Windows 7 image all the user gets is a black screen.

      This is due to a conflict between the WDDM video driver that the XenDesktop VDA installs and the version that VMware tools installs. When VMware Tools 4.1 (Version 8.x) is installed the default video driver is set to the VMware SVGA 3D (Microsoft Corporation – WDDM) driver and when you install the XenDesktop VDA it replaces the VMware driver with the Citrix Display Driver (Citrix Systems - WDDM) as the default video driver. If you leave the XenDesktop WDDM driver installed the remote console in vSphere has very poor video performance which causes the mouse to be very choppy and not responsive. If you update the video adapter to use the VMware SVGA 3D driver then the remote console works correctly however your users will get nothing but a black screen when logging into XenDesktop. To resolve this driver issue try the following:

      • Launch the vSphere client
      • Open a remote session to your gold image machine
      • If the XenDesktop VDA is installed uninstall it and reboot
      • Open device manager and change the default VMware video adapter to use the VMware SVGA II driver and reboot (Driver is located at C:\Program Files\Common Files\VMware\Drivers\Video)
      • Log back into your golden machine and confirm that video performance in the remote console works normally
      • Now we need to install the VDA without the Citrix WDDM driver as outlined in CTX130851
        • Open a command prompt and browse to \\<VDA Installation files>\x64\XenDesktop Setup (Substitute x86 for x64 if you are using a 32-bit operating system
        • Run the following: XenDesktopVdaSetup.exe /NOCITRIXWDDM (This will install the VDA without the WDDM driver
        • After the install completes reboot the system
      • Once the machine reboots log back in and open Device Manager
      • Navigate down to the Display adapters and expand it
      • You should now have two display adapters listed
        • Citrix Systems Inc. Display Driver
        • VMware SVGA II
      This configuration will allow you to use the remote console feature of the vSphere client properly and allow users to launch a XenDesktop session successfully. The only gotcha that I have found so far is when I’m using the remote console  from time to time the session will freeze and you have to reset the virtual machine. Hopefully with the newer releases of vSphere the issue is resolved.

      Saturday, January 26, 2013

      Your Profile was not loaded correctly error on windows 7

      I’ve had a few instances lately where corrupt profiles have prevented me from logging into with a Windows 7 or Server 2008 R2 machine. At the time of logon, the logon process takes a while and then I get the following error:

      Your user profile was not loaded correctly. You have been logged on with a temporary profile. Changes you make to this profile will be lost when you log off. Please see event log for details or contact your administrator.

      Also in the Event Viewer (Application) you have an entry for Event ID 1511. Normally this isn’t a big deal because you can log onto the machine with a different admin account and delete the problem profile. Only in this case when you go to remove the profile it doesn’t exist. I came across the following Microsoft article – KB947242 that deals with this issue. If you open regedit and Navigate to:

      HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfielList

      You will find a list of profiles that are identified by their SID. Locate the SID of the account in question (It will probably be called SID.bak) and delete the entry. Log off of the system and log back in using the problem account.

      Wednesday, January 23, 2013

      System Center 2012 SP1 Drops

      It’s been just over a week since the official announcement that service pack 1 for System Center Configuration Manager 2012 was released. This is a really important release for the System Center teams as SP1 really drives home the idea of unified device management. Service Pack 1 adds support for  Windows Server 2012 and Windows 8, Windows 8 tablet plus added support for Mac OS X, Linux and Unix platforms. This is exciting for our environment because there has always been a gap with managing the subset of machines running Mac OS X or Linux. Can you manage one of these platforms to the level that you can manage the Windows platform? No. However this is a step in the right direction. Admins want a single pane of glass view for managing their environment – SP1 moves System Center in the direction. Some other features of this release are support for Windows Embedded devices, full PowerShell support, Windows Azure based Distribution Points and the ability to subscribe to email alerts. 
      When you dig a little deeper into the CM 2012 release you’ll find added support for user profile and data management with their new User Environment Virtualization product (MDOP 2012) and real time administrative tasks for endpoint protection, network cost support for application delivery, updates to Bitlocker including TPM and PIN, and the ability to deploy Windows 8 applications.

      Sunday, January 20, 2013

      Troubleshooting a XenDesktop Issue... What do the Logs Say?

      Over the years when working with System Center Configuration Manager you get used to combing logs to resolve issues. ConfigMgr has a log for everything so it was my surprise when I starting working with XenDesktop how limited logging is out of the box. After working through my first major outage, I quickly found out that logging is no good if it is not enabled. It’s not that XenDesktop doesn’t have logging it just doesn’t have enabled by default. I would highly recommend enabling the following logging in XenDesktop – on the VDA, on the DDC and PorrtICA.

      Enabling Virtual Desktop Agent (VDA) logging (CTX117452):
      • Change your vDisk to Private mode and boot your template machine
      • Log in with an admin account
      • Navigate to %ProgramFiles%\Citrix\Virtual Desktop Agent
      • Backup WorkstationAgent.exe.config
      • Open the configuration file with a program such as Notepad
      • Locate the following section <appSettings> section  (Near the top of the config file) and update as follows:
        • <add key=”LogToCDF” value =”1”/>
        • <add key="LogFileName" value ="D:\XDLogs\vda_log.log"/>
        • <add key="OverwriteLogFile" value ="1"/>
      • Save and close the file
      • Restart the Citrix Desktop service or reboot your template machine and confirm that the log file gets created
      The above configuration will redirect the log file to the D:\ partition (Assuming that you have persistent disk) but you can change the location to whatever works for your environment. If you set to the location to somewhere on the C:\ drive ensure that you set the correct permissions. You can also configure the log to overwrite itself anytime that the Citrix Desktop Service starts. (Shown above) If you don’t set the log file to overwrite just be mindful of your disk space.

      Enabling Desktop Delivery Controller (DDC) logging (CTX117452) with XenDesktop 5.6:
      • Log into your DDC with an admin account
      • Navigate to %ProgramFiles%\Citrix\Broker\Service
      • Backup BrokerService.exe.config
      • Open the configuration file with a program such as Notepad
      • Locate the following section <appSettings> section  (Near the top of the config file) and update as follows:
        • <add key="LogToCDF" value ="1"/>
        • <add key="LogFileName" value ="D:\XDLogs\controller_log.log"/>
        • <add key="OverwriteLogFile" value ="1"/>
      • Save and close the file
      • With XenDesktop 5.6 I did not have to enable logging for CdsPoolMgr.exe.config as outlined in CTX117452
      • Restart the Citrix Broker Service (This will cause any virtual desktops connected to the server to re-register with another controller)
      The above configuration will create a log file on the D:\ partition assuming that you have one. If you set the log location to be somewhere on your C:\ partition watch that your permissions are set correctly. Since the log file will only overwrite itself when the Citrix Broker service is restarted this log file can grow quite large. Personally I only enable this logging when I’m troubleshooting a specific issue and then I leave it disabled.

      Enabling PortICA logging (CTX118837):
      • Change your vDisk to Private mode and boot your template machine
      • Log in with an admin account
      • Navigate to %ProgramFiles%\Citrix\ICAService\XML (If the XML folder does not exist, create one)
      • Create an new XML file called PorticaConfig.XML
      • Paste the following into the file:
      • <?xml version="1.0" encoding="utf-8"?>
        <Config xmlns="Portica.xsd">
                <Portica>
                <LogFile>
                    <LogLevel>5</LogLevel>
                </LogFile>
                <CdfTrace>
                    <LogLevel>5</LogLevel>
                </CdfTrace>
                <FunctionTrace>
                    <LogLevel>5</LogLevel>
                </FunctionTrace>
            </Portica>
        </Config>
      • Save and close the file
      • Restart the Citrix ICA service or reboot your template machine
      You can change the level of logging with the following values 0, 1, 5 or 9 with 0 being the least verbose. Unfortunately you can not change the directory where the log file gets created so you if you use a standard vDisk that gets refreshed at every logoff you’ll need a shutdown script to copy the log to either a persistent disk or a file share. By default on Windows XP the log file is located at: C:\Documents and Settings\LocalService\Local Settings\Temp and on Windows 7 it’s located at %WinDir%\ServiceProfiles\LocalService\AppData\Local\Temp

      There is also a logging tool that Citrix has published as outlined in CTX127492 that can enable more logging however I have solved most of my issues using VDA, DDC and PortICA logging. Regardless of how you setup logging a great utility to help you read them is Trace32.exe from the ConfigMgr toolkit. Download and install the tools and then open your log files with Trace – your eyes will thank you.

      Monday, September 17, 2012

      Where can I find that GPO setting?

      Is there a policy for that? Would that be a computer based policy or a user based policy? If I can’t set that with a traditional group policy can I do it with a preference? When dealing with Group Policy Objects (GPOs) I find myself asking these types of questions all the time? Wouldn’t it be nice if there was a searchable site of policy settings? Sure you can Google settings and there are great sites such as www.gpanswers.com but I’m talking about a site that allows you to search for group policy settings, identifies where you can set them, explain what they do and most importantly what registry settings they touch.  There is. MSDN publishes a site that does this. Group Policy Search is a fantastic resource when dealing with group policies. When you search for setting the tool will provide you with the following information:
      • Policy Name
      • Category Path (Where you can find it in the console)
      • Supported Platforms (What the minimal operating system level required)
      • Registry Key
      • Value
      • Explanation of what the policy does
      If you’re like me and deal regularly with group policy administration you’ll find this tool a huge time saver. And yes it has just been updated for Windows 8 and Windows Server 2012

      Tuesday, September 11, 2012

      WMI and the ConfigMgr Client

      If you still manage Windows XP machines with ConfigMgr I’m sure that you know that 9 out of 10 client health issues are WMI related. Whether it’s the CCM namespace getting corrupt or the entire WMI repository getting corrupt... Windows XP WMI + ConfigMgr = unstable.
      Most of the time you can get away with simply deleting the ccm namespace and then reinstalling the ConfigMgr client to correct the problem. (More on that later) However there are times when the fix requires you to rebuild the entire WMI repository – which should be used as a last resort as there could be other applications on the machine that rely on WMI.
      After searching around for WMI resources I came across this post which does a great job of detailing different ways to resolve your WMI issues based on your Operating System version. I've used many of these approaches in order to resolve client health issues but I’ve had the most success with the following command:
      • From a command prompt run rundll32 wbemupgrd, RepairWMISetup
      If you decide that rebuilding the WMI repository is what you need to do follow these steps for Windows XP:
      • Open a command prompt and run the following
        • net stop winmgmt
      • Browse to %windir%\System32\Wbem
      • Rename the Repository folder
      • Go back to your command prompt and run the following to rebuild your repository
        • net start winmgmt
      As mentioned before, If you rebuild your WMI repository you run the risk of breaking other applications on that machine that require WMI. A safer method is to simply delete the CCM namespace and then repair the ConfigMgr client. One tool that I now use almost exclusively is SCCM Client Center. SCCM Client Center allows you to do a variety of things but one of the most handy options are it’s client repair options. After you install Client Center connect to the machine in question, (Top left-hand corner) click on the Agent Action menu (highlighted in the screen shot below) and as you can see there are a bunch of actions that you can kick off to repair the ConfigMgr client. Most of the time selecting Delete root \ccm will resolve your problem.

      image

      I find myself using this tool everyday for a variety of reasons.

      Monday, April 30, 2012

      Task Scheduler Does Not Save Network Credentials

      Whether it’s PCI, HIPAA, CSOX or another compliance program that effects your organization, server hardening is most likely part of the program. Its one thing to provision a hardened server and then get you application installed and working correctly – your server’s behaviour doesn’t change after it’s provisioned. However when the hardening settings are pushed out post production the server’s behavior may change where things that once worked no longer do. For example recently I had an issue where a scheduled task on one of my servers would no longer store the network credentials of the service account that was running the job. What once worked, no longer did.

      After a little digging I found that a security setting on the box had been updated. The following setting, Network access: Do not allow storage of credentials or .NET Passports for network authentication had been changed from disabled to enabled in the local security policy. For more information on this setting check out TechNet. Once this setting was reverted back to the default setting the scheduled task get be set to use a domain service account.

      Monday, March 19, 2012

      PowerPoint causes 100% CPU usage in a seamless XenDesktop session


      For last couple of days I’ve been trying to determine the root cause of a problem that I was having with PowerPoint and XenDesktop. The scenario was a Windows XP workstation with Office 2010 being launched in a seamless XenDesktop 5.0 SP1 session on a dual monitor machine. Whenever I opened PowerPoint it would cause Explorer.exe to use 100% CPU and render the virtual machine useless. The issue did not occur if I started PowerPoint in safe mode. After much trial and error and countless searches online I came across the following Citrix article that was just published – CTX132436. It’s not the exact setup that I had but it did bring to attention the Disable hardware graphics acceleration setting in the Advanced options of PowerPoint. Once I enabled this option PowerPoint could open in a seamless session without pinning the CPU. 

      This setting is a per-user setting so you will need to apply it to every user that logs on. To deploy this via GPO you will need to download the Office 2010 ADM, ADMX/ADML files from here. Once you have downloaded and installed them, (Note if you use ADM files you’ll need to add them to your policy using Add/remove Templates from within the GPO) open your GPO editor
      • Navigate to User Configuration\Policies\Administrative Templates\Microsoft Office 2010\Miscellaneous
      • Set Do not use hardware graphics acceleration to Enabled

      Wednesday, February 15, 2012

      ConfigMgr Reports Prompts for a Password

      Out of the blue my web reporting for ConfigMgr started prompting for a password and no matter what account you entered it would be rejected. If you cancelled the prompt you would receive an access denied error. My reporting site was setup properly with all of the correct prerequisites as it had been online for a couple of years. Nothing seemed to work – no recent patches had been installed, logs were clean, permissions looked correct, IISRESET didn’t nor did a system reboot. Reports would also work fine from a local session on the site server. After much digging I finally came across a post on the TechNet forums that resolved the issue. Here are the steps that helped resolve the issue:

      ·         Open IIS Manager and navigate to your SMS_Reporting site
      ·         Click on the site and select Authentication under IIS from the main screen
      ·         From the Action pane select Providers
      ·         Ensure the NTLM is listed and it is at the top of the list
      ·         Open a command prompt and run IISRESET
      After that I could access reports locally and from a remote session. All the more reason to migrate my ConfigMgr reporting to SQL Reporting Services.

      Sunday, February 12, 2012

      PXE test request failed, status code is -2147467259, Error receiving replies from PXE server


      Recently OSD on my primary site server stopped working – but only when connecting via PXE. If I was using an existing boot disk, I could connect and start the imaging process. The PXE control log had the following entry over and over:

      “PXE test request failed, status code is -2147467259, Error receiving replies from PXE server”

      I assumed that the Windows Deployment Services Server (WDS) service had stopped and all I had to do was restart it and it would start responding to PXE requests. I was correct on one thing, the WDS service had stopped however when I tried to restart the service I got a very similar error in the event viewer as references in this forum post:

      Log Name: System
      Source: Service Control Manager
      General: The Windows Deployment Services Server service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 600000 milliseconds: Restart the service.


      Log Name: Application
      Source: Application Error
      General: Faulting application name: svchost.exe_WDSServer, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
      Faulting module name: wimgapi.dll, version: 6.1.7600.16385, time stamp: 0x4a5be09a
      Exception code: 0xc0000005
      Fault offset: 0x0000000000032a8e
      Faulting process id: 0x1338
      Faulting application start time: 0x01cbfecfb154f4f3
      Faulting application path: C:\Windows\system32\svchost.exe
      Faulting module path: C:\Windows\system32\wimgapi.dll
      Report Id: f089f975-6ac2-11e0-9ddc-005056970055


      After rebooting the server the same error was logged and WDS would not start. Even after removing the boot image from my distribution points and then adding them back - WDS would still not start. I tracked them problem down to recent driver addition to the WinPE boot image. It looked like when ConfigMgr was recompiling the WIM file it corrupted the image. To resolve this issue I did the following:
      ·         Remove the boot image from all distribution points (monitoring the distmgr log file)
      ·         Removed all drivers from the WinPE image
      ·         Added all our drivers back to the image and allowed it to recompile
      ·         Added the boot image back to the distribution points (monitoring the distmgr log file)
      ·         When everything had replicated successfully I was able to restart the WDS service

      Thursday, October 6, 2011

      Merging Group Policies with PowerShell

      As most environments grow they end up having many group polices enforcing a variety of different settings. At a certain point they become unmanageable and are in need of a cleanup. Merging GPOs is a pain as there isn’t really a good way of doing it – without PowerShell anyway. We faced this exactly scenario recently and lucky for us we came across this blog post by Ashley McGlone on TechNet. His script takes advantage of the Get-GPRegistryValue function to capture all of the settings and then copies them to a destination policy.

      #--------------------------------------------------------------------
      # Copy GPO Registry Settings
      # Ashley McGlone, Microsoft PFE
      # http://blogs.technet.com/b/ashleymcglone
      # January 2011
      #
      # Parameters:
      # dom FQDN of the domain where the GPOs reside
      # src string name of the GPO to copy settings from
      # dest string name of the GPO to copy settings to
      # newDest switch to create dest GPO if it does not exist
      # copymode part of GPO to copy: all, user, computer
      #--------------------------------------------------------------------

      Param (
      $dom,
      $src,
      $dest,
      [switch]$newDest,
      $copymode
      )

      # We must continue on errors due to the way we enumerate GPO registry
      # paths and values in the function CopyValues.
      $ErrorActionPreference = "SilentlyContinue"
      $error.PSBase.Clear()

      Import-Module ActiveDirectory
      Import-Module GroupPolicy

      #--------------------------------------------------------------------
      # Help
      #--------------------------------------------------------------------
      if ($dom -eq $null -and `
      $src -eq $null -and `
      $dest -eq $null -and `
      $copymode -eq $null) {
      ""
      "Copy-GPORegistryValue by Ashley McGlone, Microsoft PFE"
      "For more info: http://blogs.technet.com/b/ashleymcglone"
      ""
      "This script copies registry-based GPO settings from one GPO into another."
      "Use this script to copy and/or merge policy settings."
      "NOTE: This version does not copy GPO preferences."
      ""
      "Syntax:"
      ".\Copy-GPRegistryValue.ps1 [-dom DomainFQDN] -src `"Source GPO`""
      " -dest `"Destination GPO`" [-newDest]"
      " [-copymode all/user/computer]"
      ""
      "The -dom switch will default to the current domain if blank."
      "The -copymode will default to all if blank."
      "The -newDest switch will create a new destination GPO of the specified"
      "name. If the GPO already exists, then the copy will proceed."
      ""
      Return
      }

      #--------------------------------------------------------------------
      # Validate parameters
      #--------------------------------------------------------------------
      if ($dom -eq $null) {
      $dom = (Get-ADDomain).DNSRoot
      } else {
      $dom = (Get-ADDomain -Identity $dom).DNSRoot
      If ($error.Count -ne 0) {
      "Domain name does not exist. Please specify a valid domain FQDN."
      $error
      Return
      }
      }

      if ($src -eq $null) {
      "Source GPO name cannot be blank."
      Return
      } else {
      $src = Get-GPO -Name $src
      If ($error.Count -ne 0) {
      "Source GPO does not exist. Be sure to use quotes around the name."
      Return
      }
      }

      if ($dest -eq $null) {
      "Destination GPO name cannot be blank."
      Return
      } else {
      if ($newDest -eq $true) {
      $desttemp = $dest
      $dest = New-GPO -Name $desttemp
      If ($error.Count -ne 0) {
      "The new destination GPO already exists."
      "Do you want to merge into this GPO (y/n)?"
      $choice = Read-Host
      if ($choice -eq "y") {
      $dest = Get-GPO -Name $desttemp
      } else {
      Return
      }
      }
      } else {
      $dest = Get-GPO -Name $dest
      If ($error.Count -ne 0) {
      "Destination GPO does not exist. Be sure to use quotes around the name."
      Return
      }
      }
      }

      if ($copymode -eq $null) {
      $copymode = "all"
      } else {
      if ($copymode -ne "all" -and `
      $copymode -ne "user" -and `
      $copymode -ne "computer") {
      "copymode must be one of the following values:"
      "all, user, computer"
      Return
      }
      }
      #--------------------------------------------------------------------


      #--------------------------------------------------------------------
      # Echo parameters for this run
      #--------------------------------------------------------------------
      ""
      "Domain: $dom"
      "Source GPO: $($src.DisplayName)"
      "Destination GPO: $($dest.DisplayName)"
      "New Destination: $newDest"
      "CopyMode: $copymode"
      ""
      #--------------------------------------------------------------------


      #--------------------------------------------------------------------
      # Copy GPO registry values recursively beginning at a specified root.
      #--------------------------------------------------------------------
      # THIS IS THE HEART OF THE SCRIPT.
      # Essentially this routine does a get from the source and a set on
      # the destination. Of course nothing is ever that simple, so we have
      # to account for the policystate "delete" which disables a setting;
      # this is like a "negative set".
      # We recurse down each registry path until we find a value to
      # get/set.
      # If we try to get a value from a path (non-leaf level), then we get
      # an error and continue to dig down the path. If we get a value and
      # no error, then we do the set.
      # User values have a single root: HKCU\Software.
      # Computer values have two roots: HKLM\System & HKLM\Software.
      # You can find these roots yourself by analyzing ADM and ADMX files.
      # It is normal to see an error in the output, because all of these
      # roots are not used in all policies.
      #--------------------------------------------------------------------
      Function CopyValues ($Key) {
      $Key
      $error.PSBase.Clear()
      $path = Get-GPRegistryValue -GUID $src.ID -Key $Key
      $path
      If ($error.Count -eq 0) {
      ForEach ($keypath in $path) {
      $keypath
      $keypath | ForEach-Object {Write-Host $_}
      If ($keypath.HasValue) {
      $keypath.PolicyState
      $keypath.Valuename
      $keypath.Type
      $keypath.Value
      If ($keypath.PolicyState -eq "Delete") { # PolicyState = "Delete"
      Set-GPRegistryValue -Disable -Domain $dom -GUID $dest.ID `
      -Key $keypath.FullKeyPath -ValueName $keypath.Valuename
      } Else { # PolicyState = "Set"
      $keypath | Set-GPRegistryValue -Domain $dom -GUID $dest.ID
      }
      } Else {
      CopyValues $keypath.FullKeyPath
      }
      }
      } Else {
      $error
      }
      }
      #--------------------------------------------------------------------


      #--------------------------------------------------------------------
      # Call the main copy routine for the specified scope of $copymode
      #--------------------------------------------------------------------
      Function Copy-GPRegistryValue {

      # Copy user settings
      If (($copymode -eq "user") -or ($copymode -eq "all")) {
      CopyValues "HKCU\Software"
      }

      # Copy computer settings
      If (($copymode -eq "computer") -or ($copymode -eq "all")) {
      CopyValues "HKLM\System"
      CopyValues "HKLM\Software"
      }
      }
      #--------------------------------------------------------------------

      # Start the copy
      Copy-GPRegistryValue

      # ><>

      Steve Jobs 1955 - 2011

      Like him or not, Steve Jobs was one of the greatest innovators of our time. His creative vision saved Apple from the brink in the late nineties and turned it into a consumer electronics powerhouse. Just look at how the iPod, iPad and the iPhone has changed our lives. With his health failing he passed the torch one final time to now CEO and Chairman of the board Tim Cook this past August. It will be interesting to see how Apple fairs in the coming years without the innovation and creativity of Jobs. He touched a lot of people and his loss will be felt throughout the world.

      "The world rarely sees someone who has had the profound impact Steve has had, the effects of which will be felt for many generations to come. For those of us lucky enough to get to work with him, it’s been an insanely great honor. I will miss Steve immensely."

      - Bill Gates

      Tuesday, August 23, 2011

      An error occurred when loading the task sequence

      Recently I ran into a problem where I was unable to open and edit any of my task sequences. It didn’t matter whether I was accessing ConfigMgr from a remote console or locally on one of my site servers – they would fail to open. The error that I was getting:

      "An error occurred when loading the task sequence"
      I tried rebooting the problem site server but still no luck. According to KB2468097 this is caused because the BDD_* WMI classes are no longer correctly registered under the \root\SMS\site_ namespace in WMI.
      • Close all of your remote and local SCCM admin console sessions
      • Log on to your Configuration Manager server and select Start -> All Programs -> Microsoft Deployment Toolkit -> Configure ConfigMgr Integration
      • In the Configure ConfigMgr Integration wizard, select “Remove the ConfigMgr custom action definitions” and then click next to remove all the definitions
      • Re-run Configure ConfigMgr Integration again, and select “Install the ConfigMgr extensions”
      I also found that my site server needed to be rebooted after following the steps outlined above before the issue was resolved. This problem occurred on consecutive days a few weeks back but has yet to resurface since.

      Friday, July 22, 2011

      KB982399 - ConfigMgr site server stops responding while processing status messages


      I find that from time to time a ConfigMgr site will stop responding. Some of the first symptoms that are noticed are software distribution will stop, site backups fail and you no longer get site status messages. In the Application event viewer you may notice the following error:

      A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SMS_EXECUTIVE service.

      Generally restarting the SMS Executive service and the SMS Site Component Manger service or rebooting your site server will resolve the issue. (Temporarily) Microsoft has released a hotfix for ConfigMgr SP2 site servers that resolves this issue http://support.microsoft.com/kb/982399 According to the article the issue is caused by a deadlock situation in the SMS Executive service. I’ve applied the hotfix to one of my problematic site servers and I have not experienced a reoccurrence of this issue.