Creating Compliance Base line and SCCM site upgrade

Опубликовано: 23 Сентябрь 2026
на канале: Koraputia_ Uttam
16
1

Creating Compliance Base line and SCCM site upgrade.

Tips: Always test your configuration baseline and site upgrade in a lab environment before production rollout. For baselines, start with a small pilot collection. For upgrades, snapshot your SCCM VM or ensure DB backups are solid.


Performing a Site Upgrade in SCCM
Upgrading the SCCM site ensures you’re on the latest build (important for patching, Intune integration, and Windows 11 support).

Preparation:

Backup SCCM database (critical).

Check prerequisites (disk space, SQL version, ADK version).

Review release notes for the target SCCM build.

Upgrade Steps:

Download latest SCCM build from Microsoft.

Run Splash.hta → Choose Upgrade this site.

Follow wizard:

Accept license terms.

Install prerequisite files.

Validate readiness checks.

Upgrade process runs:

Site server updates.

Console updates.

Client agents update automatically (can take time).

Post-upgrade tasks:

Verify site version in Administration → Site Configuration → Sites.

Update boot images, ADK, and MDT if needed.

Test client communication and deployments.

Creating a Configuration Baseline in SCCM
A Configuration Baseline lets you evaluate compliance across devices (e.g., registry settings, software versions, patches).

Steps:

Open SCCM Console → Go to Assets and Compliance.

Configuration Items → Create a new item (e.g., registry key, file existence, software version).

Define settings (what to check).

Define compliance rules (expected values).

Create Baseline → Right-click Configuration Baselines → Create Configuration Baseline.

Add one or more Configuration Items.

Optionally add software updates or scripts.

Deploy Baseline → Right-click baseline → Deploy.

Choose collections (e.g., All Windows 10 Devices).

Set schedule (e.g., every 7 days).

Monitor Compliance → Check Monitoring → Deployments for compliance results.

👉 Example: You want to ensure all endpoints have a specific registry key set. Create a CI for that registry key, add it to a baseline, and deploy it to your device collection.