Microsoft

Microsoft Endpoint Configuration Manager Feedback

Suggestion box powered by UserVoice - Update: Microsoft will be moving away from UserVoice sites on a product-by-product basis throughout the 2021 calendar year. We will leverage 1st party solutions for customer feedback. Learn more

Ideas

What features would you like to see?

All of the feedback that you share in these forums will be monitored and reviewed by the Microsoft engineering teams responsible for building Microsoft Endpoint Configuration Manager, though we canā€™t promise to reply to all posts.

Please do not use UserVoice to report product bugs or for assisted support.
If you believe you have found a product bug, please send us a bug report through the Configuration Manager Console (1806 and newer). To do this, press the šŸ™‚ button in the top right corner and choose ā€œSend a Frownā€. For more details, see https://docs.microsoft.com/en-us/sccm/core/understand/find-help.

If you require assisted support, please see https://aka.ms/cmcbsupport for more details.

Standard Disclaimer ā€“ our lawyers made us put this here ;-)
We have partnered with UserVoice, a third-party service, so you can give us feedback. Please note that the Microsoft Endpoint Configuration Manager feedback site is moderated and is a voluntary participation-based project. Please send only feature suggestions and ideas to improve Configuration Manager. Do not send any novel or patentable ideas, copyrighted materials, samples or demos. Your use of the portal and your submission is subject to the UserVoice Terms of Service & Privacy Policy, including the license terms.


  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Compliance Settings - Scripttype - check on returncode than stdout output

    It would be useful, if a compliancesetting scripttype would be able to check the compliance based on the return value rather than all the Output of Stdout.
    Now the only way for me is, piping cmds to Out-Null, to ensure that a item can get compliant:

    p = some.exe |out-null
    if ($p.ExitCode -eq 0){Write-Host "SUCCESS"}
    else{Write-Host "FAILURE"}

    But for developing/troubleshouting purposes it would be nice, if i havent to catch all stdout output, especially for longer scripts, or tools, which i cannot modify ( 3rd Party vendor )

    8 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    Noted  ·  0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  2. Desired Configuration - Remediation Client Log

    Currently, there is no client logging when a Configuration Item is remediated. This is all that there is:

    1) An entry in CIAgent.log:
    "Invocation succeeded for policy platform job <GUID>"

    2) 2 entries in %PROGRAMFILES%\Microsoft Policy Platform\PolicyPlatformClient.log:
    "Starting job [<GUID>] with the following parameters"
    "Mode = Remediate, JobPriority = Foreground, PrincipalId = [SYSTEM], ScopeFilters = # filter[s]"

    The other other place that there's evidence of remediation are in the Baseline reports on the client and the SSRS reports on the server.

    None of these locations show any detail about when individual configuration items were remediated. I recently had to troubleshootā€¦

    8 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  3. Improve the usability of Compliance Settings

    When I first looked at Compliance Settings I could not get my head around how it worked. I believe I understand it now but it could be made easier.

    One useful feature would be the inclusion of using admx or existing GPOs to ensure AD compliance is working or apply settings over multiple domains / workgroup system. The Security Compliance Manager has some of these features but only for Microsoft related products with security configuration.

    7 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    Noted  ·  2 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  4. Configuration Item Checkout

    When automating the creation of Configuration Items, every time a new setting is added the version increments. Depending on my input file, the revision could be in the upper hundreds, particularly when adding Windows Defender and Firewall exceptions.

    It would be nice to check out a configuration item, make the necessary edits, and then check in the changes.

    7 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  5. Have remediation option for Compliance to immediately deploy package and run exe or script from package

    Sometimes when remediating non-compliant Compliance Items, other files may be required. In order to do this currently, it is necessary to create a collection that queries the compliance status of the compliance item, and then deploy a package to that collection. This adds a delay in processing, as it is now necessary for the collection to evaluate before deploying the package. Additionally, if the collection evaluation runs at a quicker schedule than compliance evaluation, the remediation package may run multiple times before compliance has been updated.

    It would be helpful for compliance to have the ability to deploy a packageā€¦

    7 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    Noted  ·  1 comment  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  6. Enable Windows 10 Developer Mode

    With Windows 10, there is an optional feature for Developer Mode. Enabling Developer mode on a Windows 10 workstation managed by SCCM fails with the warning "Advanced development features could not be located in Windows Update". I would ask that SCCM be able to manage Windows 10 optional features such as developer mode and not default to Windows Update.

    Start - Settings - System - Apps and Features - Manage Optional Features - Add Feature

    7 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  7. Add a tab to Configuration Baseline properties that lists contained Config Items

    Similarly to how the "deployment types" tab is in a parent Application, it would be really convenient if Config Baselines had a "Configuration Items" tab where you could open the properties of those CI's, rather than having to check the properties and switch over to the CI node in the console to check the details of what you're deploying.

    6 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  8. Display all Actions in software center under actions tab.

    Display all Actions in software center under actions tab.

    6 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  9. Allow folders under Global Conditions

    Allow folders to be created under Global Conditions to allow for better organization with in the console.

    5 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    1 comment  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  10. DCM - Expand the Compliance Rules so that they can return Values

    Expand the capabilities of the Compliance rules so that I can collect the Registry Value optionally.

    Itā€™s great that we can tell if systems are compliant, but often we are Auditing Registry values and handing the data over to Security or other groups. Those other groups determine if the setting is compliant or not.

    Simply handing over a report that lists 10s of thousands of systems as not compliant is not enough...the next question that we are often asked is what are the Non-Compliant values.

    An additional check box to "Collect Values" would be very helpful and reduce allot ofā€¦

    5 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    Noted  ·  4 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  11. Report on Local Admin Permissions

    For many years now Microsoft has strongly recommended that Local Admin Rights be removed. Would it be possible to have SCCM report on the contents of the Local Administrators group? Also, could we maybe have a wizard under Compliance Settings to configure these settings. I know Sherry Kissenger from MNSCUG has done a lot of work with this. Maybe the product team could pattern the solution after her work.

    5 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    2 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  12. VLSC license counting and yearly even up

    A tool in Configuration Manager that will reconcile installed Microsoft products taken from inventory with what is licensed in VLSC to make the yearly even up process simple and accurate.

    4 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  13. Expand Compliance Settings for Conditional Access for SCCM Clients

    Settings management in ConfigMgr is very rich and extensible. However, there are only a few settings available for Conditional Access policy managed by the ConfigMgr client (Bitlocker, Software Updates compliance, Antimalware, and AAD reg). Expand the existing compliance settings feature set, to Conditional Access clients, to allow a more compreshensive compliance evaluation criteria and to provide remediation functionality.

    4 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  14. Add an option to execute a Task Sequence to remediate a Configuration Item instead of a script.

    We are using a Baseline to monitor a set of applications on a device, so that when we switch to a new baseline (new software) a device becomes non-compliant and then runs a Task Sequence to install the new application(s) and become compliant again (it's a long story and a customer requirement that we prove 100% that the correct software is installed.

    We use a Task Sequence to remediate the device as it needs to be done in a controlled manner and it would be nice if you could select and execute a task sequence rather than waiting for theā€¦

    4 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  15. devices compliance status on SUG - drill into non-compliant list/collection/query

    on the software update dashboard I want to monitor and pursue the non-compliant machines - I cannot see a way, as in other pie charts and other graphs in the various dashboards around the console, of drilling into the list of devices

    4 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  16. Please finish implementing the Set-CMComplianceSupportedPlatform powershell cmdlet

    The Set-CMComplianceSupportedPlatform does not seem to be finished. When I use it against a CI it states the following:
    $CIRule | Set-CMComplianceSupportedPlatform
    WARNING: The 'Set-CMComplianceSupportedPlatform' cmdlet is a beta-quality and is not yet complete. It may not be fully functi
    onal, and may be changed or removed in a future release. It is provided for testing purposes and should not be used for produ
    ction purposes.

    I don't have a way to set which OSes apply to a configuration item via powershell. See this forum post for more info.
    https://social.technet.microsoft.com/Forums/en-US/b494dc56-2952-4bf6-809e-481628ceafec/setting-configuration-item-supported-platforms-with-powershell?forum=ConfigMgrCBGeneral

    4 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  17. Convert CI from Operating System type to Application Type

    It happens (quite often) when I'm creating a CI in the console that I blaze thru the wizard (accepting defaults) and start building out all my settings, rules, etc. When I'm all done, I close out and then realize that I forgot to configure the CI as an APPLICATION CI with a detection method.

    So now I have to delete my CI, and start all over from scratch. ANNOYING! I would love the ability to "convert" an Operating System CI type to an Application CI type and be able to go back in and add a detection method as appropriate.

    4 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  18. deployment under software update groups

    I wish the deployments under Software Groups would show percent compliance

    4 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  19. Make it possible to use CMpivot queries (KQL) to create Compliance Settings.

    With the ability to use CMPivot queries (KQL) it would be easier to create Compliance Settings. You could use one language for multiple tasks.

    4 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  20. To deploy a compliance policy, user's security role needs Modify permissions on Site

    For users assigned custom RBAC roles. They're unable to deploy compliance policies - with permissions Site - modify - No
    The operation fails with error "You do not have security rights to perform this operation"
    The security role needs to have Site - modify - Yes.
    Customer claims prior to 1710, this was possible.
    Other deployments like applications, packages are working with Site - modify - No

    4 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base