SCCM Outage On-going: Workarounds and Solutions

We have fixed a number of issues with SCCM and now have some workarounds for others which are listed below.  We are continuing to work on an automated a fix to ensure all clients are fully operational again as soon as possible.

If you have client PCs with any of the following issues, and need them working ASAP, please try the relevant workaround described below:

Issue 1: SCCM clients were not authenticating. Software updates and advertised programs will not run.

Cause: Residual issue from certificate issues weeks ago where W7 clients now have 2 certificates. One should have been marked as revoked but wasn’t. The other was correct but failed to work.

Work around solution: Delete both certificates from the computer’s personal certificate store. Reboot to encourage a new certificate. Reboot to get SCCM client working again. We will continue to work on an automated solution.

a)       Go to StartRun, type mmc and press Enter.

b)       Go to FileAddRemove Snap-In Add. Highlight Certificates, click Add, select Computer Account, click Finish.

c)       Select Local Computer and click Finish.

d)       Close the Add Standalone Snap-In dialog box and click OK.

e)       Browse to Certificates Personal Certificates.

f)        Delete the certificates with the computer name in the issued to column.

Issue 2: OSD media gets an error retrieving policy: 0x80004005. Log says failed to get client identity.

Solution: We have created new boot media with a newer version of the latest certificate and all IT staff will need to update their boot media.  We have added this boot image to the Live Core Task Sequences, the Beta Task Sequence, and both live and beta templates only.

Issue 3: Multicast has not been working from SCCM-Distro1

Issue 4: Hardware inventory not working on most clients

3 and 4 Solved: The work we have done on the certificates and management point has solved these issues.  We removed any reference to Network Load Balancing (NLB) which we no longer use and created a new management point certificate. We now have multicast working from all distribution points. We have also eliminated a large number of other errors in the logs of the management point and sccm-dbase.

We apologise for any inconvenience caused and will update you again when there is further progress.

Kind Regards,

IT Services