Skip to content

Commit 4a903df

Browse files
authored
Merge pull request #5948 from MicrosoftDocs/release-cm2107-hfru
Release CM 2107 HFRU
2 parents b46588c + e8d3784 commit 4a903df

11 files changed

Lines changed: 249 additions & 13 deletions

File tree

memdocs/configmgr/core/clients/manage/cmg/modify-cloud-management-gateway.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Modify a CMG
33
titleSuffix: Configuration Manager
44
description: If you need to change the configuration, you can modify the cloud management gateway (CMG).
5-
ms.date: 09/30/2021
5+
ms.date: 10/25/2021
66
ms.prod: configuration-manager
77
ms.technology: configmgr-client
88
ms.topic: how-to
@@ -39,7 +39,7 @@ After you create a CMG, you can modify some of its settings. Select the CMG in t
3939

4040
- **Verify Client Certificate Revocation**: If you didn't originally enable this setting when you created the CMG, you can enable it afterwards after you publish the CRL. For more information, see [Publish the certificate revocation list](security-and-privacy-for-cloud-management-gateway.md#publish-the-certificate-revocation-list).
4141

42-
- **Enforce TLS 1.2**: The CMG enables this option by default. Require it to use the TLS 1.2 encryption protocol. For more information, see [How to enable TLS 1.2](../../../plan-design/security/enable-tls-1-2.md).
42+
- **Enforce TLS 1.2**: The CMG enables this option by default. Require it to use the TLS 1.2 encryption protocol. Starting in version 2107 with the [update rollup](../../../../hotfix/2107/11121541.md), this setting also applies to the CMG storage account.<!--10800237--> For more information, see [How to enable TLS 1.2](../../../plan-design/security/enable-tls-1-2.md).
4343

4444
- **Allow CMG to function as a cloud distribution point and serve content from Azure storage**: The CMG enables this option by default. If you plan on targeting deployments with content to clients, you need to configure the CMG to serve content.<!--1358651-->
4545

memdocs/configmgr/core/clients/manage/cmg/security-and-privacy-for-cloud-management-gateway.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ description: Learn about guidance and recommendations for security and privacy w
55
author: aczechowski
66
ms.author: aaroncz
77
manager: dougeby
8-
ms.date: 08/02/2021
8+
ms.date: 10/25/2021
99
ms.topic: conceptual
1010
ms.prod: configuration-manager
1111
ms.technology: configmgr-client
@@ -99,6 +99,8 @@ This subset provides administrators with more control over security. The CTL res
9999

100100
Use the CMG setting to **Enforce TLS 1.2**. It only applies to the Azure cloud service VM. It doesn't apply to any on-premises Configuration Manager site servers or clients.
101101

102+
Starting in version 2107 with the [update rollup](../../../../hotfix/2107/11121541.md), this setting also applies to the CMG storage account.<!--10800237-->
103+
102104
For more information on TLS 1.2, see [How to enable TLS 1.2](../../../plan-design/security/enable-tls-1-2.md).
103105

104106
### Use token-based authentication

memdocs/configmgr/core/clients/manage/cmg/setup-cloud-management-gateway.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ description: Use this step-by-step process for setting up a cloud management gat
55
author: aczechowski
66
ms.author: aaroncz
77
manager: dougeby
8-
ms.date: 09/20/2021
8+
ms.date: 10/25/2021
99
ms.topic: how-to
1010
ms.prod: configuration-manager
1111
ms.technology: configmgr-client
@@ -94,7 +94,7 @@ Do this procedure on the top-level site. That site is either a standalone primar
9494
9595
1. By default, the wizard enables the option to **Verify Client Certificate Revocation**. A certificate revocation list (CRL) must be publicly published for this verification to work. For more information, see [Publish the certificate revocation list](security-and-privacy-for-cloud-management-gateway.md#publish-the-certificate-revocation-list).
9696

97-
1. By default, the wizard enables the option to **Enforce TLS 1.2**. This setting requires the Azure VM to use the TLS 1.2 encryption protocol. It doesn't apply to any on-premises Configuration Manager site servers or clients. For more information, see [How to enable TLS 1.2](../../../plan-design/security/enable-tls-1-2.md).<!-- SCCMDocs-pr#4021 -->
97+
1. By default, the wizard enables the option to **Enforce TLS 1.2**. This setting requires the Azure VM to use the TLS 1.2 encryption protocol. It doesn't apply to any on-premises Configuration Manager site servers or clients. Starting in version 2107 with the [update rollup](../../../../hotfix/2107/11121541.md), this setting also applies to the CMG storage account.<!--10800237--> For more information, see [How to enable TLS 1.2](../../../plan-design/security/enable-tls-1-2.md).<!-- SCCMDocs-pr#4021 -->
9898

9999
1. By default, the wizard enables the option to **Allow CMG to function as a cloud distribution point and serve content from Azure storage**. If you plan on targeting deployments with content to clients, you need to configure the CMG to serve content.
100100

memdocs/configmgr/core/plan-design/configs/support-for-windows-11.md

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -69,6 +69,16 @@ For more information on Windows lifecycle, see the [Windows lifecycle fact sheet
6969

7070
- OS deployment images and upgrade packages for Windows 11 show the image name as Windows 10. For more information, see [Using deployment tools with Windows 11 images](/windows-hardware/manufacture/desktop/using-deployment-tools-with-windows-11).<!--11128713-->
7171

72+
## Windows 11 on ARM64
73+
74+
<!-- 10589908 -->
75+
76+
Configuration Manager version 2107 with the [update rollup](../../../hotfix/2107/11121541.md) supports the client on Windows 11 ARM64 devices.
77+
78+
The **All Windows 11 (ARM64)** platform is available in the list of supported OS versions on objects with requirement rules or applicability lists.
79+
80+
OS deployment isn't supported, except for a feature update task sequence. You can deploy a task sequence with a feature update to a Windows 11 on ARM64 device. For more information, see [Upgrade Windows to the latest version](../../../osd/deploy-use/upgrade-windows-to-the-latest-version.md).
81+
7282
## Support for Windows Insider
7383

7484
You can [update and service Windows Insider](../../../sum/get-started/configure-classifications-and-products.md#bkmk_WIfB) builds. This ability is provided as a convenience to our customers. While this functionality should work, its support is best effort. Configuration Manager might not issue a hotfix for this functionality if it doesn't work.

memdocs/configmgr/core/servers/deploy/install/release-notes.md

Lines changed: 13 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Release notes
33
titleSuffix: Configuration Manager
44
description: Learn about urgent issues that aren't yet fixed in the product or covered in a Microsoft Support knowledge base article.
5-
ms.date: 08/31/2021
5+
ms.date: 10/25/2021
66
ms.prod: configuration-manager
77
ms.technology: configmgr-core
88
ms.topic: troubleshooting
@@ -115,6 +115,18 @@ To work around this issue, temporarily uninstall the later version of Visual C++
115115

116116
## OS deployment
117117

118+
### Image servicing with Windows Server 2022
119+
120+
<!-- 11843519, MEMDocs#2108 -->
121+
122+
_Applies to: version 2107_
123+
124+
If you try to [apply software updates to an image](../../../../osd/get-started/manage-operating-system-images.md#apply-software-updates-to-an-image) for Windows Server 2022, no updates display as available to install.
125+
126+
This issue is caused by a change to the Windows update category for Server 2022.
127+
128+
To resolve this issue, install the [update rollup](../../../../hotfix/2107/11121541.md) for Configuration Manager version 2107.
129+
118130
### Task sequence and application policy issue
119131

120132
<!-- 10506770 -->

memdocs/configmgr/core/servers/deploy/install/remove-central-administration-site.md

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Remove CAS
33
titleSuffix: Configuration Manager
44
description: Remove the central administration site (CAS) to simplify your Configuration Manager infrastructure to a single, standalone primary site.
5-
ms.date: 08/02/2021
5+
ms.date: 10/15/2021
66
ms.prod: configuration-manager
77
ms.technology: configmgr-core
88
ms.topic: conceptual
@@ -43,9 +43,6 @@ If the hierarchy consists of the central administration site (CAS) and a single
4343
- Data warehouse service point
4444
- Cloud management gateway (CMG)
4545

46-
> [!NOTE]
47-
> If you enabled the CMG for content, plan to redistribute the content after you recreate the CMG on the primary site.<!-- 6608659 -->
48-
4946
- Turn off distributed views
5047

5148
- Configuration Manager automatically handles package source locations for built-in packages, like the Configuration Manager client. Review all other content source locations to make sure they aren't using a share on the CAS.

memdocs/configmgr/develop/adminservice/custom-properties.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Custom properties for devices
33
titleSuffix: Configuration Manager
44
description: Use the administration service to set custom property data on devices, for reporting or collections.
5-
ms.date: 09/10/2021
5+
ms.date: 10/25/2021
66
ms.prod: configuration-manager
77
ms.technology: configmgr-sdk
88
ms.topic: how-to
@@ -107,7 +107,7 @@ where SMS_G_System_ExtensionData.PropertyName = "AssetTag" and SMS_G_System_Exte
107107
```
108108

109109
> [!NOTE]
110-
> Incremental collection updates don't work with custom properties WQL statements.<!--10901844-->
110+
> To use custom properties WQL statements with incremental collection updates, use Configuration Manager version 2107 with the [update rollup](../../hotfix/2107/11121541.md) or later.<!--10964944-->
111111
112112
## Next steps
113113

Lines changed: 209 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,209 @@
1+
---
2+
title: Update rollup for Microsoft Endpoint Configuration Manager version 2107
3+
titleSuffix: Configuration Manager
4+
description: Update rollup for Configuration Manager 2107
5+
ms.date: 10/27/2021
6+
ms.prod: configuration-manager
7+
ms.technology: configmgr-core
8+
ms.topic: reference
9+
ms.assetid: 6fb1ecf7-f7fa-4221-a3af-a6165862e1cb
10+
author: bhuney
11+
ms.author: brianhun
12+
manager: dougeby
13+
---
14+
15+
# Update rollup for Microsoft Endpoint Configuration Manager version 2107
16+
17+
*Applies to: Configuration Manager (current branch, version 2107)*
18+
19+
## Summary of KB11121541
20+
21+
This article describes issues that are fixed in this update rollup for Microsoft Endpoint Configuration Manager current branch, version 2107. This update applies both to customers who opted in through a PowerShell script to the early update ring deployment, and customers who installed the globally available release. For more information on changes in Configuration Manager version 2107, see:
22+
23+
- [What’s new in version 2107 of Configuration Manager current branch](../../core/plan-design/changes/whats-new-in-version-2107.md)
24+
- [Summary of changes in Microsoft Endpoint Configuration Manager current branch, version 2107](../../hotfix/2107/10096997.md)
25+
26+
This update also adds support for devices running Windows 11 ARM64. For more information, see [Support for Windows 11 in Configuration Manager](../../core/plan-design/configs/support-for-windows-11.md#windows-11-on-arm64).
27+
28+
## Issues that are fixed
29+
30+
<!-- 11892479 -->
31+
- After upgrading to version 2107, one or more applications in a task sequence fail with an error resembling the following in the `smsts.log`.
32+
33+
```text
34+
Install Static Applications failed, hr=0x87d00267
35+
```
36+
37+
<!-- 11993093 -->
38+
- Offline Servicing for Windows Server 2022 operating system image fails to detect updates as applicable.
39+
40+
<!-- 10555301 -->
41+
- The **Installation Status** tab in Software Center hangs without loading completely. When this issue occurs, errors resembling the following are repeated in the `scclient.log`.
42+
43+
```text
44+
Getting all instances of CCM_Application
45+
Getting all instances of CCM_Program
46+
Getting all instances of CCM_SoftwareUpdate
47+
```
48+
49+
<!-- 10692952 -->
50+
- The **CMTrace** log file viewer does not display all characters at the beginning of a line.
51+
52+
<!-- 10732477 -->
53+
- Syntax highlighting for PowerShell ignores the back quote escape character (\`\) when escaping double quotation marks.
54+
55+
<!-- 10732503 -->
56+
- The site server may stop processing state messages, resulting in a backlog of files, due to a primary key constraint violation. Errors resembling the following are recorded in the `statesys.log` file.
57+
58+
```text
59+
SQL MESSAGE: spProcessStateReport - Error: Message processing encountered a SQL error 2627 at record 100 for TopicType 500, StateID 1: "Violation of PRIMARY KEY constraint 'SR_MissingMessageRanges_PK'. Cannot insert duplicate key in object 'dbo.SR_MissingMessageRanges'. The duplicate key value is (123456, 112233).", Line 0 in procedure ""
60+
```
61+
62+
<!-- 10732515, 10745070 -->
63+
- A console extension may fail to import with an error resembling the following recorded in the `AdminUI.ExtensionInstaller.log` file.
64+
65+
```text
66+
Return code indicates unhandled case. Result: Exception of type 'System.OutOfMemoryException' was thrown.
67+
```
68+
69+
<!-- 10745061, 10745082 -->
70+
- The Configuration Manager console generates an exception when selecting **View Collection** from the Collections tab in the Devices node. The exception contains information resembling the following.
71+
72+
```text
73+
The requested object information could not be retrieved. Refresh the Configuration Manager console to verify that another administrator has not moved or deleted the object, or that the role-based administration security scopes or security roles for the object or current user have not changed.
74+
ConfigMgr Error Object:
75+
instance of __ExtendedStatus
76+
{
77+
Operation = "GetObject";
78+
ParameterInfo = "SMS_DeviceCollectionMember.SiteID=\"{Site_ID}\"";
79+
ProviderName = "WinMgmt";
80+
};
81+
Error Code:
82+
NotFound
83+
```
84+
85+
<!-- 10745095 -->
86+
- The Configuration Manager client is blocked from sending endpoint analytics sensor events to the management point. This happens when there are backlogs in the CCM_SensorMessageQueue in WMI. Errors resembling the following are recorded in the `SensorEndpoint.log` file.
87+
88+
```text
89+
Invoke SensorWmiProvider succeeded.
90+
QueryTraceW returned=234 for SensorFramework-Live-Etw...
91+
Failed to get the next message to send. 0x80041032
92+
```
93+
94+
<!-- 10748788 -->
95+
- The Configuration Manager console terminates unexpectedly if a Reporting Services Point is installed while the SQL Server Reporting Services (SSRS) service is stopped. The `AdminUI.log` file contains errors resembling the following.
96+
97+
```text
98+
System.ArgumentException
99+
Version string portion was too short or too long.
100+
```
101+
102+
<!-- 10789923 -->
103+
- The **Configuration Manager Support Center Client Tools** application terminates unexpectedly on a Windows 11 computer selecting different deployments.
104+
105+
<!-- 10789925 -->
106+
- The Cloud Management Gateway Azure Storage Account can now be configured to use TLS 1.2 through the Configuration Manager console. For more information, see [Enforce TLS 1.2](../../core/clients/manage/cmg/security-and-privacy-for-cloud-management-gateway.md#enforce-tls-12).
107+
108+
<!-- 10800388 -->
109+
- Improvements to the Data Warehouse synchronization process are included to prevent the SQL Server TempDB from filling up.
110+
111+
<!-- 10800703 -->
112+
- Endpoint analytics sensor data now includes the system SKU and processor name, and Microsoft Surface Model information, for Windows 11 hardware readiness.
113+
114+
<!-- 10944353 -->
115+
- The cloud service configuration file (.csfg) is not updated after deploying a cloud management gateway. Errors resembling the following are recorded in the `CloudMgr.log` file.
116+
117+
```text
118+
ERROR: TaskManager: Task [UpdateServiceConfigurationTask: Service {ID}] has failed. Exception Hyak.Common.CloudException, ChangeDeploymentConfigurationOperationFailed: The Change Deployment Configuration operation failed for the domain '{ID}' in the deployment slot 'Production' with the name '{ID}-deployment': 'The specified configuration settings for Settings are invalid. Verify that the service configuration file is a valid XML file, and that role instance counts are specified as positive integers.'..~~
119+
```
120+
121+
<!-- 10959492 -->
122+
- Incremental collection updates don't work when the WQL statements contain custom properties.
123+
124+
<!-- 10973090 -->
125+
- In some scenarios the maximum client policy size is incorrectly limited to 16MB instead of 32MB. This results in errors resembling the following in the `smsts.log` file.
126+
127+
```text
128+
Request was successful.
129+
dwBodyLength <= m_nMaxReplySize, HRESULT=80004005
130+
reply message body length is too long (18291682, 16777216)
131+
```
132+
133+
<!-- 10997261 -->
134+
- The BitLocker recovery key is only escrowed for the first user on a computer instead of all users that log on.
135+
136+
<!-- 11007543 -->
137+
- Clients fail to download content from a peer cache source under the following conditions:
138+
139+
- The content is deleted from a distribution point but remains in the peer cache.
140+
- The client is on a low bandwidth connection that causes the BITS download job to take over 24 hours to complete.
141+
142+
<!-- 11041519 -->
143+
- The device collection is unexpectedly empty when selected from the device graph on the Windows 10 dashboard.
144+
145+
<!-- 11184150 -->
146+
- The list of BitLocker recovery keys is blank for Azure Active Directory-joined devices.
147+
148+
## Hotfixes that are included in this update
149+
150+
- KB [10503003](../../hotfix/2107/10503003.md) Update for Microsoft Endpoint Configuration Manager version 2107, early update ring
151+
152+
## Known issues in this release
153+
154+
- The **Log Analytics connector for Azure Monitor** feature was removed from Configuration Manager version 2107. However, the pages that allow an administrator to view and delete the **OMS Connector** are still present but don't function. For more information, see [Deprecated features](../../core/plan-design/changes/deprecated/removed-and-deprecated-cmfeatures.md#unsupported-and-removed-features).
155+
156+
## Update information for Microsoft Endpoint Configuration Manager current branch, version 2107
157+
158+
This update is available in the Updates and Servicing node of the Configuration Manager console for environments that were installed by using early update ring or globally available builds of version 2107.
159+
160+
Members of the Configuration Manager Technology Adoption Program (TAP) must first apply the private TAP rollup before this update is displayed.
161+
162+
To verify which build is in use, look for a Package GUID by adding the Package GUID column to the details pane of the Updates and Servicing node in the console. The update applies to installations from packages that have the following GUIDs:
163+
164+
- **248DC1EB-4B98-4483-BAF3-08C678C1CD0A**
165+
- **142D394F-4E40-4574-AB8F-D182200DF03C**
166+
- **8D0F9A5B-B21D-438F-AC56-38428FECB787**
167+
- **86FE4AF1-68A1-4AD4-B435-91995D30ECD6**
168+
- **E392EF90-DB2C-47BB-ACB8-11E702D0F451**
169+
- **42E1CF6E-95A1-4A8D-96AD-311E6247B3FB**
170+
171+
The update is also applicable to TAP builds with the private TAP rollup installed.
172+
173+
### Restart information
174+
175+
This update does not require a computer restart but will initiate a [site reset](../../core/servers/manage/modify-your-infrastructure.md#bkmk_reset) after installation.
176+
177+
### Additional installation information
178+
179+
After you install this update on a primary site, pre-existing secondary sites must be manually updated. To update a secondary site in the Configuration Manager console, select **Administration** > **Site Configuration** > **Sites** > **Recover Secondary Site**, and then select the secondary site. The primary site then reinstalls that secondary site by using the updated files. Configurations and settings for the secondary site are not affected by this reinstallation. The new, upgraded, and reinstalled secondary sites under that primary site automatically receive this update.
180+
181+
Run the following SQL Server command on the site database to check whether the update version of a secondary site matches that of its parent primary site:
182+
183+
```code
184+
select dbo.fnGetSecondarySiteCMUpdateStatus ('SiteCode_of_secondary_site')
185+
```
186+
187+
- If the value 1 is returned, the site is up to date, with all the hotfixes applied on its parent primary site.
188+
- If the value 0 is returned, the site has not installed all the fixes that are applied to the primary site, and you should use the **Recover Secondary Site** option to update the secondary site.
189+
190+
## Version information
191+
192+
The following major components are updated to the versions specified:
193+
194+
| Component | Version |
195+
|-------------------------------|------------------|
196+
| Configuration Manager console | 5.2107.1059.3700 |
197+
| Client | 5.0.9058.1047 |
198+
199+
## File information
200+
201+
File information is available in the downloadable [KB11121541_FileList.txt](https://aka.ms/KB11121541_FileList) text file.
202+
203+
## Release history
204+
205+
- October 27, 2021: Initial hotfix release
206+
207+
## References
208+
209+
[Updates and servicing for Configuration Manager](../../core/servers/manage/updates.md)

memdocs/configmgr/hotfix/TOC.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,8 @@ items:
77
href: 2107/10096997.md
88
- name: KB 10503003 Early update ring
99
href: 2107/10503003.md
10+
- name: KB 11121541 Update rollup for 2107
11+
href: 2107/11121541.md
1012
- name: Version 2103
1113
items:
1214
- name: KB 9210721 Summary of changes in 2103

0 commit comments

Comments
 (0)