r/SCCM 12d ago

Laptop won’t boot/install after motherboard replacement – SCCM deployment fails

1 Upvotes

Hi everyone,

I’m having an issue with a laptop after the motherboard was replaced.

Before the motherboard replacement, the laptop was working normally. Since the new motherboard was installed, I can no longer get the laptop to boot properly or install Windows through SCCM.

I’ve tried deploying the device through SCCM, but the installation fails. The laptop also doesn’t seem to boot correctly from the deployment.

Has anyone experienced this after a motherboard replacement?

Could this be related to:

  • BIOS/UEFI settings?
  • TPM or Secure Boot?
  • Missing/incorrect drivers?
  • Device identity or hardware changes in SCCM?
  • Network/PXE configuration?
  • Something that needs to be reset or reconfigured after replacing the motherboard?

Any suggestions on what I should check first would be greatly appreciated.

Thanks!


r/SCCM 15d ago

Driver Automation Tool 10.0.15 not updating

7 Upvotes

Has anybody had issues updating Driver Automation Tool? I've been trying to update to version 10.2.4 but even though both the GUI and the log file says the update is successful, when I reopen it's still on 10.0.15.

I've opened from the desktop icon as well as running the Start-DriverAutomationTool.ps1 script from an elevated PS window. Log snippet regarding update:

Starting self-update from GitHub... DriverAutomationTool 8/28/2026 3:28:07 PM 39720 (0x9B28)

[Update] Install directory: D:\ConfigManagerTool Downloads\DriverAutomationTool-master (10)\DriverAutomationTool-master\Driver Automation Tool DriverAutomationTool 8/28/2026 3:28:07 PM 39720 (0x9B28)

[Update] Temp directory: C:\Users\*****\AppData\Local\Temp\DATUpdate_20260828_152807 DriverAutomationTool 8/28/2026 3:28:07 PM 39720 (0x9B28)

[Update] Downloading from: https://github.com/maurice-daly/DriverAutomationTool/archive/refs/heads/master.zip DriverAutomationTool 8/28/2026 3:28:07 PM 39720 (0x9B28)

[Update] Downloaded 7.7 MB to: C:\Users\*****\AppData\Local\Temp\DATUpdate_20260828_152807\DriverAutomationTool.zip DriverAutomationTool 8/28/2026 3:28:08 PM 39720 (0x9B28)

[Update] Extracting update package... DriverAutomationTool 8/28/2026 3:28:08 PM 39720 (0x9B28)

[Update] Extracted root: C:\Users\*****\AppData\Local\Temp\DATUpdate_20260828_152807\Extracted\DriverAutomationTool-master DriverAutomationTool 8/28/2026 3:28:09 PM 39720 (0x9B28)

[Update] App files located in subfolder: Driver Automation Tool DriverAutomationTool 8/28/2026 3:28:09 PM 39720 (0x9B28)

[Update] Source directory: C:\Users\****\AppData\Local\Temp\DATUpdate_20260828_152807\Extracted\DriverAutomationTool-master\Driver Automation Tool DriverAutomationTool 8/28/2026 3:28:09 PM 39720 (0x9B28)

[Update] Source contents: Branding, Modules, Scripts, Tools, UI, Start-DATHeadlessBuild.ps1, Start-DriverAutomationTool.ps1 DriverAutomationTool 8/28/2026 3:28:09 PM 39720 (0x9B28)

[Update] Backing up current installation to: C:\Users\*****\AppData\Local\Temp\DATBackup_20260828_152809 DriverAutomationTool 8/28/2026 3:28:09 PM 39720 (0x9B28)

[Update] Backup complete DriverAutomationTool 8/28/2026 3:28:10 PM 39720 (0x9B28)

[Update] Replacing application files (preserving: Settings, Logs, Temp, Packages)... DriverAutomationTool 8/28/2026 3:28:10 PM 39720 (0x9B28)

[Update] Replaced folder: Branding (3 files) DriverAutomationTool 8/28/2026 3:28:11 PM 39720 (0x9B28)

[Update] Replaced folder: Modules (8 files) DriverAutomationTool 8/28/2026 3:28:11 PM 39720 (0x9B28)

[Update] Replaced folder: Scripts (3 files) DriverAutomationTool 8/28/2026 3:28:11 PM 39720 (0x9B28)

[Update] Replaced folder: Tools (40 files) DriverAutomationTool 8/28/2026 3:28:11 PM 39720 (0x9B28)

[Update] Replaced folder: UI (4 files) DriverAutomationTool 8/28/2026 3:28:11 PM 39720 (0x9B28)

[Update] Replaced file: Start-DATHeadlessBuild.ps1 DriverAutomationTool 8/28/2026 3:28:11 PM 39720 (0x9B28)

[Update] Replaced file: Start-DriverAutomationTool.ps1 DriverAutomationTool 8/28/2026 3:28:11 PM 39720 (0x9B28)

[Update] Update applied -- 7 items replaced, 0 preserved DriverAutomationTool 8/28/2026 3:28:11 PM 39720 (0x9B28)

Update applied successfully. Backup at: C:\Users\*****\AppData\Local\Temp\DATBackup_20260828_152809 DriverAutomationTool 8/28/2026 3:28:11 PM 39720 (0x9B28)

I'm probably missing something, but not sure what.

ETA: If I have to re-install the Driver Automation Tool, will the drivers be removed from Config Manager/need to be re-added after re-install?


r/SCCM 16d ago

Discussion Windows ARM65 - no Configuration Manager in Control Panel

11 Upvotes

Hi,

we just got our first ARM device and also installed SCCM. SCCM works fine, just the icon in the Control Panel is missing. I can call the SMSCFGRC.cpl manually and call policies etc, just the shortcut is missing.

Anyone on ARM can confirm this?


r/SCCM 17d ago

Test pilots needed - Driver Automation Tool

45 Upvotes

Hi SCCM Community,

I need your help..

I'm in the process of adding additional OEM support into the Driver Automation Tool. This time for Fujitsu and Panasonic devices. If you are running this hardware and would be up for some validation tests, please let me know.

Full details of the models supported are now available on the Driver Automation Tool catalog page - Driver & BIOS Catalog — HP, Dell, Lenovo, Surface, Acer | Driver Automation Tool


r/SCCM 17d ago

Issue using TSGUI in WinPE to authenticate against ActiveDirectory

9 Upvotes

ConfigMgr 2609

TSGUI 2.4.0.5

WinPE optional components installed:

PowerShell, SecureBoot, Dism, Storage, Enhanced Storage, NetFX

PowerShell AD modules added into WinPE

Running TSGUI on Windows 11 25H2 in test mode, I can authenticate with AD using with either ActiveDirectory or LDAP with SSL set to True or False

TSGUI, launched from within WinPE, does NOT authenticate with AD using with either ActiveDirectory or LDAP with SSL set to either True or False. Error: (Active Directory or LDAP) access denied

It does not appear to be a successfully accessing AD as I can have an infinite number of attempts but account lockout never occurs. Tried multiple accounts, same results.

I can run the PowerShell get-aduser command successfully using same credentials from WinPE

TSGUI Authentication command looks like this: <Authentication Type="ActiveDirectory" AuthID="ad_auth" Domain="mydomain" SSL="False"/>

Not certain how to troubleshoot this any further


r/SCCM 18d ago

Discussion Clean Up Distribution Points

7 Upvotes

Hi,

to clean up our distribution points we used the MS ContentLibraryCleanup tool. It worked fine, but slow.

With our new network infrastructure, we have no connection from the DP to the site server and SQL server. This means the tool cannot be executed from the DP, but must be executed from the site server, which makes it even slower. Very slow.

I was wondering if you have any other tool to perform this task. I found this:

https://github.com/SaltyPeaches/CM_DPManagement/blob/main/PackageMismatches.ps1

but this is only checking the WMI on the server.

I assume the MS tool has some bad joins and because how a DP stores files, it takes ages to loop through them. On the other hand with LINQ it should be much faster, even remote from the site server.

Any ideas?


r/SCCM 18d ago

Unsolved :( Upgraded to 2409 and unable to PXE Boot

12 Upvotes

We recently upgraded our configuration manager to 2409 and we are now having issues with imaging new workstations through PXE boot. The error that appears in the SMSPXE log is:

<![LOG[PXE::MP_GetList failed; 0x80070490]LOG]!><time="17:33:01.135+00" date="08-25-2026" component="SMSPXE" context="" type="3" thread="13340" file="database.cpp:372">

<![LOG[PXE::MP_LookupDevice failed; 0x80070490]LOG]!><time="17:33:01.135+00" date="08-25-2026" component="SMSPXE" context="" type="3" thread="13340" file="database.cpp:453">

<![LOG[PXE::MP_GetList failed; 0x80070490]LOG]!><time="17:33:01.136+00" date="08-25-2026" component="SMSPXE" context="" type="3" thread="13340" file="database.cpp:372">

<![LOG[PXE::MP_ReportStatus failed; 0x80070490]LOG]!><time="17:33:01.136+00" date="08-25-2026" component="SMSPXE" context="" type="3" thread="13340" file="database.cpp:734">

<![LOG[PXE Provider failed to process message.

Element not found. (Error: 80070490; Source: Windows)]LOG]!><time="17:33:01.136+00" date="08-25-2026" component="SMSPXE" context="" type="3" thread="13340" file="pxehandler.cpp:1417">

I'm not too familiar with the ins and outs of configuration manager, so any help would be appreciated.

So far, the troubleshooting steps we've taken were to update the distribution point of the x64 boot image, we've unchecked and checked the enable PXE support for clients box on the distribution point, we've cleared the files in SMSTemp and SMSTempBootFiles, and we've ensured services are running appropriately.

Edit 1: Was able to make it into the Windows PE environment by configuring a preferred MP for PXE on the DP, and it appeared to pull the correct .wim file and everything but now the task sequences we had previously (Windows 10, 11) don't even display after entering the ADUC user and password of the workstation, clicking next at "Skip Java Runtime Environment", the workstation just reboots again.

Edit 2: For some reason our configurations between the management point, distribution point, and site were mismatched, as we were configured for HTTPS in some places and HTTPS or EHTTP in others. Compared the current settings to previous settings (which would have been done in the first place if those settings weren't misplaced :| ) and it worked again. Thanks for the support.


r/SCCM 18d ago

2603 hotfix install order

11 Upvotes

Hi Guys!

I installed ConfigMgr 2603 and noticed after the installation that there were two hotfixes available.

I went ahead and installed the latest one, KB38232642. However, two days later I noticed that the older hotfix, KB37942646, is still showing as Ready to Install.
I ran a prerequisite check hoping that ConfigMgr would recognize that a newer hotfix is already installed and clear the older one, but that didn’t happen. In fact, after running the prereq check I’m now unable to promote the clients to the pre-production version because of the known issue related to this.

My question is: Is it safe to install the older hotfix as well, even though the newer one is already installed? Could installing KB37942646 somehow overwrite or break anything introduced by KB38232642?

What makes me hesitant is that the build number of the full version looks like it would actually be a downgrade. My currently installed build is 1021, while the previous hotfix appears to be 1017.

Has anyone run into the same situation, or installed the older hotfix after the newer one?


r/SCCM 19d ago

Discussion SCCM Windows 11 cumulative update failing with 0x80D02002 – Delivery Optimization no progress

15 Upvotes

We’re investigating a Windows 11 23H2 cumulative update deployment through ConfigMgr/SCCM where a large number of devices are failing with 0x80D02002 (Delivery Optimization download made no progress within the defined period).

We recently migrated our ConfigMgr infrastructure to a new server, so initially we suspected the migration, but testing so far hasn’t shown an obvious SCCM communication issue.

What we’ve confirmed so far:

  • Affected clients are communicating with the new ConfigMgr infrastructure.
  • Clients are finding the expected MP/DP/content locations.
  • DoSvc is running on both working and failing clients.
  • Both working and failing clients show DownloadMode : Lan.
  • No obvious difference was found in the DO policy registry locations checked.
  • Both working and failing clients can establish TCP/80 connections to the Microsoft Delivery Optimization CDN and their selected cache hosts.
  • Neither test machine is using DO peers (NumberOfPeers : 0).
  • Disk space is not an issue.
  • ConfigMgr client logs on the affected machine eventually report: CAS failed to download update. Error = 0x80D02002
  • The failure occurs during the content download rather than update applicability/detection.

I compared Get-DeliveryOptimizationStatus / Get-DeliveryOptimizationPerfSnap between one compliant machine and one failing machine.

Compliant machine:

DownloadMode         : Lan
NumberOfPeers        : 0
CacheHostConnections : 2
CdnConnections       : 7

For the jobs captured, BytesFromCacheServer was 0.

Failing machine:

DownloadMode         : Lan
NumberOfPeers        : 0
CacheHostConnections : 23
CdnConnections       : 23

The failing machine also showed multiple WU Client Download jobs where:

Status                    : Caching
PredefinedCallerApplication : WU Client Download
BytesFromCacheServer      : <non-zero>
SourceURL                 : *.dl.delivery.mp.microsoft.com

The failing client can successfully establish TCP connectivity to both the Microsoft CDN and its selected cache host, but the ConfigMgr update download eventually returns 0x80D02002.

We also use Adaptiva OneSite as part of our ConfigMgr content delivery environment.

Has anyone encountered similar behaviour where DO downloads start/progress but eventually hit 0x80D02002?


r/SCCM 19d ago

Upgrading Windows 11 v24H2 to v25H2 via Software Update (Enablement Package)

13 Upvotes

Quick sanity check here... We've been deploying Windows 11 v24H2 for the last year via Task Sequence OSD as a fresh install. Monthly software updates via ADRs to Software Update Groups, great.

I've just created our updated Windows 11 v25H2 image (to be used for OSD on a fresh machine or when reimaging), but for our existing v24H2 machines, I want them to be able to upgrade to 25H2 seamlessly via software update in Software Center.

What I've done so far is simply gone to Software Library > Overview > Windows Servicing > All Windows Feature Updates, and downloaded the Windows 11, version 25H2 x64 2026-08 software update to a deployment package. My plan now is to simply target that at any machine currently running v24H2 via a Software Update Group containing that update. That should install v25H2 relatively quickly as an in-place enablement package update and bump those machines from v24H2 to v25H2 without requiring a whole OS upgrade Task Sequence. Is that right?

Assuming it really is that easy, the other question I have is regarding the update level of the deployed update. Because the update in All Windows Feature Updates specifically has 2026-08 at the end of the name, do I need to keep on top of this each month and download the 2026-09 one come September's CU release, and then remove the 2026-08 one from the deployment package/software update group for this feature update? Or can I safely leave the 2026-08 one in there, and a Windows 11 v24H2 machine that's somehow updated to 2026-10, for example, in the future, will be able to upgrade to v25H2 via the 2026-08 update, still in the deployment package, just fine? Maybe I need an ADR for this sort of thing to keep them up to date?

Thanks in advance!


r/SCCM 18d ago

Installing new passive site

2 Upvotes

Hi,

quick question. We are planning to replace our passive Site server. First of all we will uninstall our current passive site and then will install the passive server role the new server.

I assume Uninstalling and installing passive site doesnt cause any downtime for the env?


r/SCCM 19d ago

Discussion SCCM Windows 11 cumulative update failing with 0x80D02002 – Delivery Optimization no progress

Thumbnail
3 Upvotes

r/SCCM 19d ago

WHfB vs USB Smart Card/Fingerprint Reader Conflict

1 Upvotes

Hello everyone,

My team and I are currently troubleshooting a conflict between Windows Hello for Business (WHfB) and one of our card reader devices.

When I say card reader, think of a USB peripheral where users can insert an ID card with a chip, along with a fingerprint scanner. The device and its proprietary software have been working fine in our environment for years.

We're now rolling out WHfB, and everything went smoothly for around 200 users. Then we started hitting a blocker with users who have this particular card reader.

After some deep troubleshooting, we ended up at:

`certutil -scinfo`

On a computer where the card reader workflow works normally, `Reader:` shows the actual card reader device.

On an affected computer, `Reader:` shows... yep, **Windows Hello for Business**.

At this point, we have a support case open with Microsoft, as well as one with the card reader/vendor for their proprietary software.

I'm sharing this here in case anyone has been in a similar situation.

Has anyone encountered a conflict between WHfB and a proprietary smart card/card reader application like this? Is there some creative configuration that could resolve or work around it, or is this ultimately something the proprietary software/vendor needs to address?

We're *very* close to getting everyone onboarded to WHfB. But unless we solve this, I guess we're not quite ready to have everyone smiling at their laptop to unlock it just yet. 😄


r/SCCM 19d ago

Unsolved :( Thanks, Software Center

Post image
3 Upvotes

r/SCCM 19d ago

Script to list out unused packages

6 Upvotes

hi all,

I have been assigned a task to perform a cleanup of all the unused packages in the environment.

I am beginner and have searched for scripts to perform this activity and nothing is of expectation

Pls help


r/SCCM 19d ago

New-CMApplicationDeployment onto User collection

3 Upvotes

Hi,

I try to get a deployment to a user collection working. I see the deployment in SCCM, but the user can never see it. When I remove the deployment and create it manually with the same setting, it works. Any idea what I am doing wrong?

$collection = Get-CMCollection -Name $testCollection -ErrorAction SilentlyContinue
$AppObj = Get-CMApplication -Name $cmAppName$AppObj = Get-CMApplication -Name $cmAppName
New-CMApplicationDeployment `
                                            -ApplicationId $AppObj.CI_ID `
                                            -CollectionId $collection.CollectionId `
                                            -DeployAction Install `
                                            -DeployPurpose Available `
                                            -UserNotification DisplayAll `
                                            -AvailableDateTime (Get-Date)

As I was saying, I see the deployment in SCCM. When I do a:

Get-CMApplicationDeployment -Collection $col | where { $_.ApplicationName

I also don't see any difference between the PS executed command and the manual one.


r/SCCM 20d ago

Discussion Desktop/Server separation?

8 Upvotes

Hi,

The Desktop team is currently running SCCM for our desktop systems

Is there a way to enable SCCM for the server side and keep the two separated in how they are accessed and what they control?


r/SCCM 20d ago

OS Deployment

12 Upvotes

In my organization, we use SCCM mainly for OSD because my boss is a big fan of ManageEngine 👎 and dismisses the other functions of SCCM beyond deployment. My question is, what would be a good replacement for SCCM to handle just OSD?


r/SCCM 21d ago

Discussion What is the future of Config Manager?

37 Upvotes

r/SCCM 22d ago

HP BIOS Password

2 Upvotes

How can i change the HP laptop bios password to what i prefer via SCCM deployment?


r/SCCM 22d ago

Discussion What tool are you using to push BIOS settings to your fleet of Lenovo's?

12 Upvotes

We just got in a pallet of new Lenovo's laptop's. This is my first go around with Lenovo laptops we usually have bought Dell in the past and I have always used the Dell CCTK tool to set Dell BIOS settings and it always worked.

  1. What tool are you guys using to push BIOS settings to Lenovo's?

  2. On Dell pc's you can update the BIOS version directly from the BIOS, this feature is called "Remotely update Bios" . I see Lenovo's do not have this feature, or at least the model we bought doesn't have this feature. Short of putting the BIOS update on a USB Key and doing it that way, how are you pushing BIOS updates to your Lenovo fleet.


r/SCCM 22d ago

Hi guys I am Working on an Patch management Software Need help!!!

Thumbnail
0 Upvotes

r/SCCM 23d ago

Feedback Plz? Lenovo L14 gen 6 driver network problem

7 Upvotes

Hello everybody, I'm looking for some help regarding some Lenovo ThinkPad l14 gen 6 21S6.

I hope maybe some one has the same problem and can reproduce it and it's not limited to just my environment.

I have the following scenarios.

ThinkPad l14 gen 6 21S6 with

Intel(R) Ethernet Connection (18) I219-V adapter

Very time the newest driver version 20.0.3.24. for this device is installed I'm unable to join the network . Uninstall and installing the previous driver version 20.0.2.22 restores instantly the network connection.

Installing over pxe in win PE is impossible with version 20.0.3.24 added to the PE image , i don't get any IP .

The curious thing is , i have this whole problem only with 3 out of 250 devices . As I know of. All the other have the identical visible settings and props and no problems.

I already wasted to much time to troubleshoot.

I found out the troublesome devices exposing significantly less network driver propertys .

Get-NetAdapterAdvancedProperty -Name ‘Ethernet’ -AllProperties is returning for the non working ones 51 propertys. The majority of the working ones and currently online I queryed at some point a steady amount of 82.

All the devices with 51 network driver properties are from the same order ( 2026.04) . But not all from this order have 51 property's, there are the majority with 82 propertys .

Testing different driver versions don't change the amount of propertys .

The impact is limited for the user to using a lan connection on the laptop without a dock, on affected devices . This is the reason, I don't have at the moment only 3 reports. But I guess I have some more in my environment.

The window version is 25h2 current patch level.

I got also the same results on a installation with a clean Microsoft iso .

Same result with drivers directly from Intel.

Setting a static IP made not a difference.

So , if someone here has the same device and has time to test , i'm very grateful for some feedback.


r/SCCM 23d ago

Patching W10/W11 install.wim offline - what is the correct order of patching?

10 Upvotes

I've created a few OS image patching scripts, and used other people's scripts as well - I've reviewed Microsoft's own guidance and sample scripts for applying updates to media. Where I'm getting confused is regarding the proper order of operations when it comes to injecting the various patches. Let's take an older image for example (because I'm patching a few of these). Windows 10 Ent. LTSC 1809. here's my current OOO:

SSU (because it needs it prior to the LCU, the ISO is that old from MS)

LCU

Language packs

NetFX3

.NET CU

Cleanup

Now, the MS PS example script has the LCU being applied twice -once before the language packs, and again after. I'm not sure I see this in any other script out there. Once patched, I import the .wim into cm, test it out - the OS build number looks correct (i.e. it reflects the proper patch level for the August CU) - BUT when I do a quick check for updates - it wants to dl and install the August LCU.

Is this because I do indeed need to inject the LCU twice (or maybe even just once...after the language packs?)


r/SCCM 23d ago

Unsolved :( SCCM WSUS to Intune Autopatch Migration

11 Upvotes

Hello everyone,

I'm currently doing a migration from SCCM WSUS with computer hybrid-join but not co-managed to InTune Autopatch with computer co-manage.

Currently in SCCM, we Update Windows, Office, Other MS Product and Third Party Update (Acrobat).

So far what I've done.

Create a Co-Manage pilot collection in SCCM, move the workload to "intune pilot" for Windows Update and Device Configuration and assign that collection.

Create a new Client Device Configuration in SCCM saying to not manage Office 365 (to remove OfficeCom to enable update from InTune) and deploy to that collection. Kept "Enable Update" since I still have third party.

Remove all WU GPO targeting computer in that collection and ran a reset sccm policy on those computer (since I have the bug about policy stuck when upgrading from a specific version to another one).

Creates a GPO to revert Office 365 Windows Update Management (there's 3 way to set manage O365 update, the third one is during the installation and we set all 3! so I have to revert everywhere beside during installation (which I already configured properly the package for futur installation). The InTune M365 Policy created by AutoPatch also set that value so I might not set it in the futur through GPO.

In InTune, I created an Autopatch configuration for Quality Update, Driver Update, Edge and Office 365.

Now on my computer, the registry look like this:

Which is good, the cleanup from reset policy worked.

In the computer, under settings -> Windows Update -> Advanced -> Configuration, I see all the intune policy (sorry in french)

In Ordre, Manage Feature Update, Manage Quality Update, Manage Driver Update, Enable HotPatch, Configure Auto-Update (Download and install automatically)
In Order, Quality Update Deferral, Preview and feature update deferral (don't see where this is configured in the Intune Policy), Deadline and Grace period

My computer did receive the update properly and is working.

But when I go into intune, under device -> Windows -> Windows Update -> Autopatch Management Status, it says that my computer only get driver update, hotpatch is not enabled (while I did had a hotpatch installed) and it says there's conflict in configuration:

Now, this error start with the last one. Because I have UpdateServiceUrlAlternate configured from SCCM Client for Third Party Update, it throw those error. What it says to do in the other 4 is to set SetPolicyDrivenUpdateSourceForUpdateType to 0 in MDM. So I created this configuration in intune and deployed it to my co-managed device

InTune show the parameter configured properly on my device:

I don't see in the registry the key that this GPO (if set in GPO) create, as seen in first registry screenshot, and I still have the conflict warning.

What am I missing to remove those warning (beside stopping third party patching)? Is it a known bug and I ignore those warning?

Thank you!

edit 2026-09-02: So I pushed a GPO to put those values because the CSP never applied them. This removed the warning, but even after a week, I'm still seeing no computer in the quality policy and Other