Introduction

During OS deployment with SCCM, the client certificate may fail to install, causing communication issues with the management point. This article outlines steps to diagnose and resolve this issue, ensuring smooth deployment and client communication.

Identifying the Problem

During the OS deployment process, the SCCM agent may not retrieve the client certificate necessary for communication with the management point. Here’s a common scenario:

  • You deploy the OS using SCCM.
  • The SCCM client fails to get the client certificate.
  • Uninstalling the client with ccmsetup /uninstall and reinstalling it via console push works correctly, indicating no site boundary issues.

After verifying logs and reinstalling the management point, the problem persisted. The issue was finally traced to a reboot at the end of the task sequence (especially in WinPE), causing the client to enter provisioning mode.

Solution

To resolve this issue, ensure no reboots occur during the task sequence. Disable all intentional or unintentional reboots. Here’s how to check and modify your task sequence:

  1. Open the SCCM console and navigate to the Software Library workspace.
  2. Expand Operating Systems and select Task Sequences.
  3. Right-click on the task sequence in question and select Edit.
  4. Review all steps for any Restart Computer actions.
  5. Disable or remove any restart steps to prevent the client from entering provisioning mode.

After making these changes, redeploy the task sequence and verify that the client certificate installs correctly and communication with the management point is established.

For further information and solutions, you can refer to the following Microsoft blog post: Configuration Manager Blog.


0 Comments

Leave a Reply

Avatar placeholder

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.