MEMCM client not getting full policy.

Barleyologist 116 Reputation points
2021-02-19T01:34:23.783+00:00

Until recently my clients have been healthy, in the last few weeks we have discovered some, not all, clients that only get partial policy. If the client had 10 app deployed against them they might only receive 5 of those. An identical machine sitting next to it in the same collection will get all 10. Machine policy action will not cause the client to get the remaining policy. I can leave it online for days and nothing changes. The only thing that will cause the deployments to show up is to delete the deployment and re deploy, run machine policy, and the deployment will show up in minutes.

The environment is http mode. I have read every log that I could think of and nothing stands out, although I am no expert in the logs. Our domain admin recently spun up new domain controllers and retired the old ones (OS update) weeks ago but do not see how this would cause the problem we see but thought I would note. I have inquired with our security officer if there are port changes but they replied no changes but our security officer is typical and is not very forthcoming. Our Enterprise CA was recently rebuild but since we are HTTP and not HTTPS I do not see how this will effect anything, just thought I would note it. We are running a CMG but this seems to only effect the on prim clients. I have read a bunch of previously posts of similar problems and have not found anything that might be causing our problems.

I appreciate any and all assistance.

Microsoft Configuration Manager Application
Microsoft Configuration Manager Application
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Application: A computer program designed to carry out a specific task other than one relating to the operation of the computer itself, typically to be used by end users.
480 questions
Microsoft Configuration Manager
0 comments No comments
{count} votes

Accepted answer
  1. Barleyologist 116 Reputation points
    2021-02-22T20:28:53.37+00:00

    @Simon Ren-MSFT I believe I ended up finding the problem, waiting to hear back from more healthy clients to be completely sure but so far so good. I ended up determining that one applications content seemed to be corrupted in some fashion. I did not get any indication that there was any problems however while trying to manually download the content would just do nothing unlike the other deployed applications. After resolving issue the clients begin to downloaded the remaining packages. If correct the Prod Dev Team could potentially improve this process as it seems it would go down the list of apps and when it reach the troubled application it would halt. This is why some application would install and others would not. I imagine the list is likely in first deployed to most recent and why different clients got different applications. If the process was allowed to download all applications independently this situation would have been completely different leaving all machines just not displaying a single application and troubleshooting would have been much simpler. Anyways thanks for the eyes and assistance, this one was a challenge.


7 additional answers

Sort by: Most helpful
  1. Barleyologist 116 Reputation points
    2021-02-20T01:06:39.74+00:00

    I am looking at one title that is not displaying in Software Center and I see it in the Policy Evaluator it just does not show in software center;

    Same policy DEP-CSF20784-ScopeId_863CAEC2-10B8-48A4-B6A1-344BA14E0C82/Application_57a10ba1-e297-47c6-a699-9bc36e83212b:2.00 is already in the download queue.   PolicyAgent_PolicyEvaluator 2/19/2021 4:44:19 PM    14360 (0x3818)
    
    0 comments No comments

  2. Barleyologist 116 Reputation points
    2021-02-20T01:09:21.117+00:00

    winmgmt /verifyrepository comes back as [WMI repository is consistent] on the client.

    0 comments No comments

  3. Simon Ren-MSFT 33,226 Reputation points Microsoft Vendor
    2021-02-22T08:46:29.8+00:00

    Hi,

    Thanks for your detailed information. There is no error in the locationServices.log.

    1.Please help check if there is any error in the MP_Policy.log on the MP. If yes, please refer to:
    Solution: SCCM Clients Unable to Download Policy from Management Point

    2.Here is an article about client policy flow for your reference:
    Policy Flow – The Details

    Thanks for your time.

    Best regards,
    Simon

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.