Creating Compliance Base line and SCCM site upgrade.
Tips: Always test your configuration baseline and site upgrade in a lab environment before production rollout. For baselines, start with a small pilot collection. For upgrades, snapshot your SCCM VM or ensure DB backups are solid.
Performing a Site Upgrade in SCCM
Upgrading the SCCM site ensures you’re on the latest build (important for patching, Intune integration, and Windows 11 support).
Preparation:
Backup SCCM database (critical).
Check prerequisites (disk space, SQL version, ADK version).
Review release notes for the target SCCM build.
Upgrade Steps:
Download latest SCCM build from Microsoft.
Run Splash.hta → Choose Upgrade this site.
Follow wizard:
Accept license terms.
Install prerequisite files.
Validate readiness checks.
Upgrade process runs:
Site server updates.
Console updates.
Client agents update automatically (can take time).
Post-upgrade tasks:
Verify site version in Administration → Site Configuration → Sites.
Update boot images, ADK, and MDT if needed.
Test client communication and deployments.
Creating a Configuration Baseline in SCCM
A Configuration Baseline lets you evaluate compliance across devices (e.g., registry settings, software versions, patches).
Steps:
Open SCCM Console → Go to Assets and Compliance.
Configuration Items → Create a new item (e.g., registry key, file existence, software version).
Define settings (what to check).
Define compliance rules (expected values).
Create Baseline → Right-click Configuration Baselines → Create Configuration Baseline.
Add one or more Configuration Items.
Optionally add software updates or scripts.
Deploy Baseline → Right-click baseline → Deploy.
Choose collections (e.g., All Windows 10 Devices).
Set schedule (e.g., every 7 days).
Monitor Compliance → Check Monitoring → Deployments for compliance results.
👉 Example: You want to ensure all endpoints have a specific registry key set. Create a CI for that registry key, add it to a baseline, and deploy it to your device collection.