Jump to content


xc3ss1v3

URGENT! Endpoint Protection Out-of-date on ALL Clients

Recommended Posts

Hey guys...

It's come to my attention that all of our clients are now out-of-date in regard to definition updates. I will first note that our networking side did replace the firewall around the same time that this issue started. However, I don't really have any ammunition to go at them with as to why it is (if it is) their fault. This has just been one of those things that has always worked.

 

As for my set up, I have an ADR created that creates deployments for definition updates as soon as they are downloaded each day. From what I can tell, it last downloaded and deployed an update this morning around 10 a.m. So, it seems as if the issue is that the clients aren't getting the deployment. Is there a log of some sort I can look at to find potential issues?

 

Thanks in advance.

Share this post


Link to post
Share on other sites

Look at a problematic client in the Windows\CCM\Log directory in the log files that start with Update*. Those log files should give some indication if the client is still able to communicate with ConfigMgr for updates..

Thanks for the clarification. In looking at those logs, I'm not seeing any errors (that I can tell). To me, this just seems like some kind of break down of communication between the clients and servers in particular regard to SCEP. Completely at a loss ):

Share this post


Link to post
Share on other sites

Try you push the definition update from the SCCM Management Console to your client and then check the client logs. Sort the directory by date to see which logs have any changes.

Also check your windowsupdate.log for Errors.

Share this post


Link to post
Share on other sites

can you show us what your Endpoint Protection Update tab gui looks like on a client ? this will show you when it last updated and what version it's running...

Share this post


Link to post
Share on other sites

can you show us what your Endpoint Protection Update tab gui looks like on a client ? this will show you when it last updated and what version it's running...

 

Basically every client is just like this or at least similar (last update being older). We are currently blocking updating from outside sources. I did notice that in the Antimalware Policy, there is a setting that will only allow clients to update from outside sources after so many hours of not being able to update with ConfigMgr. To take that setting out of the loop, I set it for 720 hours (30 days), but the clients still don't seem to be updating. I will also note that the majority of clients haven't pulled Antimalware Policies any time recently. Is that indicative of a somewhat broken SCEP client? Note that on this particular machine (in the screenshot), it is pulling current policies.

post-20332-0-23268500-1404918307_thumb.png

Share this post


Link to post
Share on other sites

One thing I just noticed... It appears as if Default Client Antimalware Policy AND Endpoint Protection - Managed Device Policy are both deployed to clients even though I don't have Default Client Antimalware Policy actually deployed? Is that one that is applied no matter what? If so, do the settings in my custom policy override it? I currently have the custom policy order set to 1 and Default is set to 10000.

Share this post


Link to post
Share on other sites

Just to to make sure. Is the update group of your ADR holding a valid definition file?

I remember a similar situation in our environment, when the upstream WSUS ran out of disk space and could not download the newest definitions anymore.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.