Microsoft

System Center Configuration Manager Feedback

Ideas

What features would you like to see?

All of the feedback that you share in these forums will be monitored and reviewed by the Microsoft engineering teams responsible for building System Center Configuration Manager, though we can’t promise to reply to all posts.

Standard Disclaimer – our lawyers made us put this here ;-) Please note that the System Center Configuration Manager feedback site is moderated and is a voluntary participation-based project. Please do not send any novel or patentable ideas, copyrighted materials, samples or demos which you do not want to grant a license to Microsoft. See the “User Voice Terms of Service” link below for more information.

How can we improve Configuration Manager?

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Prompt users for reboot, but NEVER force it

    The reboot settings only allow for the user to postpone a reboot for up to 24 hours. Why can't we expand that time or just keep reminding them forever until they reboot themselves? The longer that they have been pending a reboot, remind (pester) them more frequently. Or auto reboot if nobody is logged on.

    306 votes
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      Noted  ·  9 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
    • Complete Group Policy Integration

      Configuration Manager should be able to configure all aspects of a workstation that can be done using other Microsoft tools. Some group policy items already exist such as folder redirection and Firewall Policies. It would be great if Firewall could be expanded to include creation of firewall exceptions. It would also be great if we could configure all group policies from within SCCM perhaps using compliance settings.

      201 votes
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        Noted  ·  14 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
      • Compliance Settings

        When defining a Configuration Item with Powershell have the possibility to influence the behavior of the script (eg -noprofile, setting allowed time to run)

        119 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          Noted  ·  6 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
        • DSC to replace or compliment basline feature

          DSC is a wonderful framework for handling baseline configurations across Windows and Linux machines, but it's completely unsupported in SCCM directly. While a Pull server is certainly more simplistic than an SCCM hierarchy, it would still be very beneficial to have some integration in a couple of areas:

          Management Points can easily be configured to host mof configurations for clients, and a new client policy class for allowing the SCCM agent to configure the pull server settings on a host would be great. Alternatively a new role could be made ... not sure that would feel as elegant.

          The baseline…

          113 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            2 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →

            This feature will evolve from the “run scripts” features that first showed up in ConfigMgr 1706 tech preview. It lets you build a library of powershell, and execute them on demand. We will evolve DSC capabilities into this feature too.

          • Allow defining custom OMA-URI settings for Windows 10 clients with ConfigMgr client

            Currently you cannot define custom OMA-URI settings for Windows 10 clients with ConfigMgr client. You can only define quite limited set of settings. Unfortunately, there are some important OMA-URI settings that should be set on all Windows 10 clients (DataProtection/AllowDirectMemoryAccess), which are not part of limited available settings.

            This is now one example, but there will be other examples in the future.

            Currently, there is not good way to deploy the setting easily to all clients in the environment.

            65 votes
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              0 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
            • Hide configuration baselines targeted to mobile devices on Windows clients

              In a hybrid environment all user targeted baselines are displayed on Configuration Manager Control Panel utility. In the attached picture from a Windows 10 client, you can see that there are baselines that make sense only on iOS/Android/WP devices.

              Those baselines shouldn't be visible on Windows ConfigMgr client. They just confuse users/admins.

              37 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                0 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
              • More accurate registry Compliance Settings

                When creating the Configuration Item (Create Configuration Item Wizard, Settings step) and choosing Registry setting type for the Create Setting window, there are some bizarre registry types mentioned in Data type drop-down box: String, Integer, Date and Time, Floating Point, Version and String Array. Most of these data types are all REG_SZ type. But where is REG_MULTI_SZ? REG_EXPAND_SZ? REG_DWORD? REG_QWORD? REG_BINARY?
                There is also possibility to set/check compliance for those registry settings with script, but why the Registry Configuration Item in first place?
                These actual registry data types need to be implemented instead of/additionally to currently existing ones.

                21 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  Noted  ·  3 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
                • Configuration Baseline Workflow

                  I'd like to see the configuration baselines expanded to include a workflow option similar to creating a task sequence.

                  This in my view should allow for conditional operators (if,or,else) to allow for greater flexibility to control a compliance state on multiple configuration items. If configuration items within this could also allow for separate or multiple options of remediation actions it would be great.

                  Furthermore if the values determined in individual configuration items could be assigned to named variables within this workflow it would allow for complex remediation tasks including passing through all or some these variables to script driven remediation…

                  15 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    2 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
                  • Add auto remediation to a Software Update compliance baseline

                    At present SU compliance baselines can identify missing updates but not remediate by installing them. Please add the option to have the missing updates installed either from a DP or Microsoft Update.

                    11 votes
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      Noted  ·  0 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
                    • Add Ability to Remediate Existential Registry Setting Compliance Items

                      Currently you cannot auto-remediate a registry compliance item with an existential rule. I should be able to select an option to auto-remediate to have a setting removed much like you can to set a value.

                      11 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        2 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
                      • Natively integrate SCAP policy enforcement into SCCM

                        Integrate the ability to natively enforce SCAP policy enforcement via SCCM. Provide the capability automatically download SCAP policies from sources such as DISA and other SCAP content providers.

                        Integrate the application of the SCAP policies into the OS provisioning processes as an option for out of the box compliance at OS deployment before the OS touches the network.

                        11 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          0 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
                        • Create and deploy Wi-Fi profiles with a password

                          Is it possible already to create and deploy Wi-Fi profiles with a password option? Without a password it seems not logical to me? Many customers are requesting this functionality for Windows 10 devices (during and after OS deployment)

                          /Henk

                          11 votes
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            2 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
                          • CIs for Mac OSX

                            Provide an easy mechanism to manage configuration items for Mac OSX without the need to create shell scripts for user or system preferences. Such as the ability to configure settings for device encryption, disabling USB, setting background images, browser home page, etc. etc. etc.

                            10 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              1 comment  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
                            • Console UI function to invoke evaluation of baselines on clients

                              Being able to invoke evaluation of baselines deployed to certain Client or device collection from the Console UI would be very helpful.

                              One way to do it would be to add the option in to the Client Notification pane or also known as the "right click tools" see Attached file.

                              I have an old blog post on how to invoke evaluation with the help of Powershell but adding it in to the Console UI would be very nice.

                              https://timmyit.com/2016/07/26/sccm-and-powershell-trigger-baseline-evaluation-on-client/

                              10 votes
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                1 comment  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
                              • ability to add a Software Update Group to a Configuration Baseline

                                currently you can only add individual updates

                                10 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
                                • Allow compliance items to be run at logon/logoff

                                  Right now, Compliance Items can only be scheduled for specific time periods. It would be helpful to schedule Compliance for logoff/logon.

                                  9 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    Noted  ·  0 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
                                  • Integrate the the SCAP Extensions. Make it easier to use, faster, and include dashboards\reports.

                                    1. Make a GUI for running the SCAP extensions. Preferably integrate the SCAP extensions into SCCM so SCAPtoDCM.exe can be run from right clicking Compliance Settings
                                    2. Reduce the amount of PowerShell code created in each Configuration Item (CI). A CI that checks for the existence of a registry key is very long. Additionally, some of the CI’s will either timeout or require an increase in the timeout time which could affect client performance.
                                    3. CI’s created should not use the oval ID as its name as it cannot be correlated to practical information. In the case of DISA STIGS,…

                                    9 votes
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Improve the usability of Compliance Settings

                                      When I first looked at Compliance Settings I could not get my head around how it worked. I believe I understand it now but it could be made easier.

                                      One useful feature would be the inclusion of using admx or existing GPOs to ensure AD compliance is working or apply settings over multiple domains / workgroup system. The Security Compliance Manager has some of these features but only for Microsoft related products with security configuration.

                                      8 votes
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        Noted  ·  2 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
                                      • Best of Configuration Items

                                        I would like to see "Top (n) Configuration Items" of world wide SCCM installs made avalable to other users for reviewing and downloading.

                                        Top (n) CI's could be rated by MS SCCM Telemetry, by other users and so forth. From the top list of CI's admins could then download either MS approved ready CI's or mockups of good methods and practices to be used in their CI's.

                                        Target would be to easilly recieve top 5-10 CI's that enterprises now use to check BitLocker status, Client Cache sizes/states etc.

                                        Posted by @arisaastamoinen

                                        7 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          1 comment  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Compliance Settings - Scripttype - check on returncode than stdout output

                                          It would be useful, if a compliancesetting scripttype would be able to check the compliance based on the return value rather than all the Output of Stdout.
                                          Now the only way for me is, piping cmds to Out-Null, to ensure that a item can get compliant:

                                          p = some.exe |out-null
                                          if ($p.ExitCode -eq 0){Write-Host "SUCCESS"}
                                          else{Write-Host "FAILURE"}

                                          But for developing/troubleshouting purposes it would be nice, if i havent to catch all stdout output, especially for longer scripts, or tools, which i cannot modify ( 3rd Party vendor )

                                          7 votes
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            Noted  ·  0 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
                                          ← Previous 1 3
                                          • Don't see your idea?

                                          Feedback and Knowledge Base