If you are using authenticated firewalls, configure the synchronization task to run in attended mode. If you are using attended mode, the synchronization component requires the following:
The attended mode has the following potential drawbacks:
For more information about configuring the synchronization component to run in attended mode, see Chapter 6, “Managing Software Updates,” in the Microsoft Systems Management Server 2003 Operations Guide.
Yes. When the Distribute Software Updates Wizard creates patch packages and programs, it does not set the Run property when a user is logged in by default. This means that patches can be installed even when users are not logged in. If necessary, you can do a completely unobtrusive and unattended patch installation by scheduling it at night when all user interfaces are turned off. Then, when users log in the next morning, they have a patched system ready to go. For urgent patches that must become active even if users have unsaved changes in open documents, you must:
For more information about creating the software updates packages, see Chapter 6, “Managing Software Updates,” in the Microsoft Systems Management Server 2003 Operations Guide.
There are certain latencies before a patch will show up in the approval list of the Wizard:
Also, there is always a chance the new patch is not really applicable for any of your computers, or that it is applicable to computers that are not being inventoried.
Ensure that the specific client meets all these requirements:
Table 2 displays the principal log files that are useful for troubleshooting issues with the SMS 2003 software update management tool. This table is more current than the table in Chapter 6, “Managing Software Updates,” in the Microsoft Systems Management Server 2003 Operations Guide.Table 2 Log Files for Troubleshooting the Software Update Management Tools
Security Update Sync Tool
(SyncXml.exe)
SecuritySyncXml.log
PatchDownloader.log
SMS Client Log folder
\%temp%
Log file for the synchronization component; used for troubleshooting firewall and authentication issues.
Microsoft Office Inventory Sync Tool for Updates
OfficeSyncXml.log
Security Update Inventory Tool
(Scanwrapper.exe)
Scanwrapper.log
Log file maintained by inventory component on SMS client computer.
Results.xml
%windir%\system32\VPCACHE\<PackageID> folder on the SMS client computer
File maintained by scan component on SMS client computer that includes output of MBSA scan, including reasons why MBSA scan detected an update as applicable.
Microsoft Office Inventory Tool for Updates
Individual Software Update log files
<qnumber>.log
%windir% folder on SMS client computer
Installation log maintained by software update installers. Contains information about actual software update installation.
Software Update Installation Agent
(Patchinstall.exe)
PatchInstall.log
SMS 2003 (no service pack): System Temp folder of the SMS client computer
SMS 2003 SP1: SMS Client Log folder
Package installation log file maintained by the Software Update Installation Agent on the SMS client computer.
User Notification
PatchUIMonitor.log
Log file contains information regarding the patch installation scheduling queue.
SMSCliUI.log
Log file contains information about user interaction with the SMS Update icon in the System Tray.
For more information about software update logging, see Chapter 6, “Managing Software Updates,” in the Microsoft Systems Management Server 2003 Operations Guide.
To remove a patch or hotfix, create a collection rule for clients based on the appropriate inventory properties for the patch, then target the uninstall program using traditional software distribution. To locate command line options for uninstall and other needed actions, see the following articles:
Did you find this information useful? Send your suggestions and comments about the FAQ to smsdocs@microsoft.com.
Top of page