Blog Post

SCCM Software Update Dashboard

Dujon Walsham • Mar 02, 2019

Available on the Technet Gallery, see your deployment forecast ahead of time!

Overview

This dashboard provides a full SPOG (Single Pane of Glass) look into your entire WSUS/SUP infrastructure to see exactly how all deployments are running, and what your overall expected successful forecast figures will be.

There are various sections which go into the dashboard so the following sections will provide a breakdown to each part of the report.

The great feature about this dashboard is that it contains a drilldown on the majority of the charts and in a neutral format as possible i.e. each chart has a drilldown with specific sections but instead of each drill down zoning only into results into a specific section it will display all the results with interactive sorting so you can see everything and also sort interactively.


Enhanced Error Code Analysis

I have pulled a list of WSUS codes from the Microsoft site and saved them into a .CSV file which I had put into a separate table in my SCCM Database which is able to be merged with a lot of the results pulled from this dashboard and has been configured so that you can see the full error message description as well as the code.

Latest Synchronization Results

Displays the latest updates which have been synchronized within SCCM in the last 7 days, also shows the same information for declined updates with both charts containing a drilldown report for each. The table information shows more specific details on the last successful and unsuccessful syncs as well as the current status of your ADR rules.

WSUS Clean-up Compliance

Shows the status of if your WSUS/SUP Servers require a clean-up to be performed or are close to needing servicing from Obsolete updates which can cause churn in the database performance on your SUSDB database, and also to check if there are updates which are failing to download updates

Successful Deployment Forecast

Breakdown of clients by hardware and further category breakdowns of online devices to measure successful patch deployment forecasts. Many devices can be unavailable from deployments which are currently scheduled and this gives a great detailed look at what your expected success rate will be. By default looks specifically at the "All Desktops and Server Clients" collection

One very different Pie chart is for Last Scan states, so this in particular will show how many of have successful scans and failed scans, as these can show if they will have problems when receiving any kind of update deployments

Definition Updates Compliance

Definition updates compliance for Windows Defender and Endpoint Protection. Ranging from up-to-date to older than 7 days. The Windows Defender section will focus specifically on the Windows 10 Devices whilst the Endpoint Protection chart will show from devices ranging at Windows 8.1 and lower

Windows 10 Cumulative Update Compliance

Chart breaks down the success rate of your cumulative update patch deployments showing all status messages from Success to devices being unknown

Current Software Update Deployment Assignments

Chart breaks down the success rate of your cumulative update patch deployments showing all status messages from Success to devices being unknown

Where to Download

This is currently available on the Technet Gallery on the link below
https://gallery.technet.microsoft.com/SCCM-Software-Update-2dbd8d6b

by D Walsham 13 Dec, 2021
Looking through the current SQL Server topology and how it affects our decision
by D Walsham 07 Oct, 2021
Introduction
by D Walsham 06 Oct, 2021
Introduction
by D Walsham 12 Aug, 2021
All the parts of the series we went into great detail about how we analyse an end to end solution and how we would design a solution in which would allow us to build endpoints without SCCM being a dependency. Whilst we did this, there is another scenario which we have not touched on yet, which is the hybrid scenarios. In a perfect world ideally you would have your Azure Active Directory within the cloud, every machine meets the recommended requirements for Windows 10, everything is imported into Intune/Autopilot and everyone is happy. But we know this isn't realistic in all cases. Many organisations cannot just simply up and go from on-premise into the cloud therefore the checkpoint here is of course getting into hybrid solutions such as; Co-Management Between Intune and SCCM Hybrid AD with Azure AD and On-Premise AD syncing together These things can play a very interesting part in how you would tackle this if you envisage the next step in the blueprint is to be in a position in which you can build and manage endpoints soley within Intune. With this final part of the series we will go in-depth in how the common hybrid setups look like and how we go about moving into the next step of being able to manage and build devices without SCCM.
by D Walsham 29 Jul, 2021
In continuation from the previous part where we had discussed how we create the "on site" piece of the solution, this was the part which would allow us to get our endpoints into a state in which they would essentially be ready to go through the Autopilot process. Which leaves our next piece of the puzzle, to begin the configuration of the actual backend side that resides within our Endpoint Management console. And you will see how everything ties up together to satisfy the full end to end process of getting an unknown (or known) device to proceed thorough the whole workflow to be finally managed by Intune without the aid of SCCM taking part in any of the prerequisites or preparation at hand.
by D Walsham 15 Jul, 2021
In this part we are now going to look into the technical step by step points on how we put everything together. In the previous part we spoke about the structure of how we would asses whether a machine was actually ready to be built with Autopilot or not with a build checklist process which would step through all areas which would cover an endpoints eligibility. Now with everything planned out we finally want to step into making things reality by putting everything together.
by D Walsham 02 Jul, 2021
When it comes to managing your endpoints in endpoint manager, one of the things you may be looking to do is to get all of your Intune registered machines to also be enrolled as Autopilot devices. Now we can of course just have the deployment profile deployed to all machines and then hit the "Convert targeted machines to autopilot" but this might not necessarily be feasible for every client. We may want to perform some due diligence first so we can at least understand what devices in Intune are not in Autopilot.
Show More
Share by: