Skip to main content

Windows Problem Record

Problem records and remediation notes for Windows UEM environments.

SCCM Client Agent not installing during autopilot

· 2 min read
Jon Griffey
IT Director for Endpoint Management

Problem Record 265079 SCCM Client Agent not installing during autopilot

Jon reported that the SCCM agent was taking a long time to install for the OAL Self Driven Autopilot enrolled devices. During the investigation and discussion we discovered that the Intune Enrollment Co-management settings were no longer applied to anything. This used to be assigned and is no longer assigned. In an effort to fix this issue we assigned it to the device scope group for all autopilot enrolled devices. After making this emergency change Jon tested it and found that it was now working as expected for the OAL self driven devices. But a few days later I became aware that the user driven autopilot was no longer working. During the investigation and troubleshooting I created a duplicate Intune Autopilot deployment profile with identical settings and replicated all the assigned groups to the new deployment profile named "_TAMU User Driven with Pre Provision v2". I then forced a autopilot enrollment sync and it successfully switch all autopilot enrollment devices over to the new profile. But this did not resolve the issue. I pulled the autopilot enrollment logs and found that it was erroring out during the sccm client installation. I was able to determine that the emergency change to assign the Co-management settings to all autopilot enrolled devices was the cause. This emergency change has been adjusted to only target the OAL and UEM devices as well as a test device and test user. I am continuing to investigate this to find out why this is not working as intended. The User driven autopilot devices are now working as expected. This downtime occurred on 7/3 and 7/4. Devices were still able to finish out the autopilot enrollment with the availability of the continue on error option. This only effected devices going through the autopilot enrollment process.

ABR Causing PowerShell Prompts to Appear In User Session

· 3 min read
Andrew Nelson
Systems Administrator II

Problem Record 154742 ABR Causing PowerShell Prompts to Appear In User Session

Reported in TDX tickets:

First Reported: https://service.tamu.edu/TDNext/Apps/34/Tickets/TicketDet?TicketID=143296

Earliest known ticket: https://service.tamu.edu/TDNext/Apps/34/Tickets/TicketDet?TicketID=139662

Additional Tickets: https://service.tamu.edu/TDNext/Apps/34/Tickets/TicketDet?TicketID=145228

On initial analysis, the problem stops occurring after reboot until the next ABR elevation, and ceases entirely when ABR is uninstalled. Potential link to Elastic ruled out, issue continues even with Elastic removed.

ABR essentially runs as a service running with full access using a Kernel level driver to the OS. Seems to be the case that some update made previously invisible scripts with an unknown criteria (we've looked for criteria) visible. The reason we see it more than others is we're updating apps silently in the background and thus running more scripts.

Timeline of problem thus far:

Graph of the occurrences of ABR as the parent process of powershell, over the last two months, as of 2025-04-24.

2025-03-03 13:39:06 The Testing - CUI Compliance - RL2: Block List subsetting was created by Andrew Nelson to support Jon Griffey's directive for testing CUI policies.

Friday 2025-03-07 05:45:00 We received email notification that ABR 8.5 was available in our environment.

Friday 2025-03-07 10:28:57 The first occurrence of a PowerShell process with ABR as the parent process is captured in Elastic's logs (henceforth event). For the entire day, 10 events occurred.

Monday 2025-03-10 95,104 events occurred over the span of the day.

Tuesday 2025-03-11 Incident #139662 was reported as the first incident associated with this problem. Event levels remained steady around this threshold until next date.

Thursday 2025-03-27 Event occurrences approximately double to 214,226

Friday 2025-3-28 Event occurrences approximately double to 480,837, and continue to rise daily until next date.

Tuesday 2025-04-15 Event levels peak at 713,321 events, then stabilize across following days between 500,000 and 650,000 occurrences daily.

Wednesday 2025-04-23 14:41:52, at the direction of Admin By Request Support, Andrew Nelson disabled the Testing - CUI Compliance - RL2: Block List subsetting, which contained a block for PowerShell.exe, but did not match or apply to any devices in our environment. Change Management was not performed proactively as these were test settings that did not apply to any devices.

Thursday 2025-04-24 daily occurrences fell to 327,143, lowest level since March. Determination was made to document as Emergency Change to cover retroactive nature of documentation, in consultation with Kari Stiller. Change #184369 was drafted.

Friday 2025-04-25 Change #184369 is initially submitted. Daily occurrences fell to 107,733 as of 15:00:00.

Hourly graph reflects continued downward trend.