Microsoft

System Center Configuration Manager Feedback

Ideas

What features would you like to see?

All of the feedback that you share in these forums will be monitored and reviewed by the Microsoft engineering teams responsible for building System Center Configuration Manager, though we can’t promise to reply to all posts.

Standard Disclaimer – our lawyers made us put this here ;-) Please note that the System Center Configuration Manager feedback site is moderated and is a voluntary participation-based project. Please do not send any novel or patentable ideas, copyrighted materials, samples or demos which you do not want to grant a license to Microsoft. See the “User Voice Terms of Service” link below for more information.

How can we improve Configuration Manager?

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Exclude virtual cluster and OU from discovery

    Please add the ability in discoveries to:
    - exclude OU's
    - exclude Virtual Cluster resource

    60 votes
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      6 comments  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
    • Remove Custom Discovery Data

      When creating custom discovery data using the smsresgen class there is no way to remove this from the discovery related tables in ConfigMgr. Since there is a supported way to add this data, there should be a supported way to remove it. This is necessary as a rollback option, to return ConfigMgr to its default state, before the custom discovery data was added.

      50 votes
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        Noted  ·  0 comments  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
      • AD Group Discovery should not write DDR for invalid records

        When System Discovery finds an object that seems invalid, currently it won`t be imported (which is good).
        ERROR: System <systemname> is a unsupported operating system, unsupported version, or malformed AD entry. Reported system type is: ().
        However if the same object has an AD Group Membership and AD Group Discovery finds it, it won't check if it is valid, but write the DDR and create the object record in SCCM DB.

        Please change AD Group Discovery so it validates new objects too.

        35 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          Noted  ·  1 comment  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
        • Allow the ability through Config Manager Client Settings to set Deferral of Upgrades (CB/CBB) for Windows 10 Clients

          It would be ideal to be able to defer feature upgrades for Windows 10 via Client settings to avoid having to use a GPO. This would avoid the current dual scan issue with GPOs and WUfB Policy Settings.

          15 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            0 comments  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
          • AD System Discovery - Skip the DNS Check Please!

            Please add a check box which would enable me to have the DNS check skipped during computer system discovery. There are situations when a system may not resolve in DNS from the CM server, however I would still like to have the attribute data (LastLogon, pwdLastSet, etc) from Active Directory updated by the discovery process regardless of the DNS check. Currently these values are not updated if the system is not found.

            14 votes
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              1 comment  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
            • AD System/User discovery on disabled accounts

              SCCM is not synchronizing disabled accounts, so it is not synchronizing the change in the UserAccountControl-attribute, so from SCCM perspective every machine/user is active. This creates problems e.g. in Software Asset Management since collections can’t select AD active accounts only. SCCM should synchronize changed attributes or at least UserAccountControl of AD disabled accounts if the account exists in SCCM

              14 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                2 comments  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
              • Make Software Inventory scan cycle useful again

                Software Inventory scan cycle (file scanning) of just Program Files can be ridiculously slow where it can run for over 12 hours or more which impacts all other inventory scan cycles. Worse still, if user powers down or restarts client the scan restarts from scratch. Disabling throttling is still too slow ( due to its use of WMI according to Tier 3) and not supported.
                We would like a usable Software (file) Inventory scan cycle.

                12 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  0 comments  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
                • reboot pending reporting

                  Could you implement a reboot pending check in the console ?

                  this is not an easy way to implement reporting on it :
                  http://blogs.technet.com/b/smartinez/archive/2014/06/27/reboot-pending-report-how-to-create-the-report.aspx

                  11 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    0 comments  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
                  • AD Group discovery discovering group members

                    AD Group discovery automatically discovers all computers and users that are members of the group (and nested groups). Sometimes it is not desired, as we choose what computers/users we want to discover via AD System/User Discovery. AD Group discovery should update group membership information for existing resources in the site. Or, ideally, provide an option to choose if we want to also discover group members, or not.

                    8 votes
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      1 comment  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
                    • Allow different Discovery Schedules for each configured location

                      We have many Discovery locations configured but we do not need discovery to run against them all on the same schedule. For example, we have many smaller domains where new objects are rarely created. We should be able to discover these environments less often than a workstations OU in our primary domain. The option to set both the Full and Delta discoveries would be ideal. This could extend to group and other discovery types as well.

                      7 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        2 comments  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
                      • Allow options we discover machines in AD in ConfigMgr without having to resolve them

                        Allow options we discover machines in AD in ConfigMgr without having to resolve them

                        5 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          1 comment  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
                        • Missing WMI Classes needeed for Security Features

                          For Windows 10 Credential Guard:
                          -Processor class lacks information if Virtualization is enabled
                          -Processor class lacks information if VT-x is enabled
                          -No information available if Secure Boot is enabled (I had to add a custom MOF (local|HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\SecureBoot\\State|UEFISecureBootEnabled)

                          4 votes
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            0 comments  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
                          • Allow exclusion of OU's from Active Directory User and System Discovery

                            Have the ability to include/exclude certain OU's from both Active Directory User and System Discovery.

                            E.G. I might have an "All Users and Groups" OU at the root domain level, which may contain sub OU's containing service accounts or mailbox accounts etc. that I don't want being picked up by discovery. The ability to pick which sub OU's to discover/not discover would be really handy in this scenario. The same applies for system/computer discovery also.

                            4 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              0 comments  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
                            • force client discovery restricted by AD container

                              when you want to force client discovery, it is done on all containers set in discovery settings. It will be easier to be able to force discovery for for single container (discovery on all containers can take hours - not easy for testings when new container is added).

                              3 votes
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                0 comments  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
                              • Network Discovery

                                Current NW discovery not provide device details.. device Type as Router Printer or Switch, AP, identification Name. Also not has completed discovery details to manage these devices in Console

                                3 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
                                • Option to perform AD group discovery from MP in respective domain instead of Site Server

                                  In scenario where SCCM is deployed across multiple domains, when we want to perform AD group discovery (or other AD related discoveries) we have to allow our Site Server to reach all the domain controllers of all the different domains, however often that is not possible due to security restrictions (firewall openings not allowed).

                                  However since we have MP in each domain it would be beneficial to have an option to perform these discoveries from the management points as they have all the required access to respective domains domain controllers (in terms of firewall openings).

                                  This could be available as…

                                  3 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    0 comments  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
                                  • Made Windows Server 2016 Std Evaluation compatible with SCCM CB 1606

                                    Hi,

                                    Detected as an unsupported operating system for the moment, in sytem discovery:
                                    INFO: discovered object with ADsPath = 'LDAP://*.*.*/CN=W2016SRV,CN= SMS_AD_SYSTEM_DISCOVERY_AGENT
                                    INFO: Property (operatingSystem) for (W2016SRV) was not set SMS_AD_SYSTEM_DISCOVERY_AGENT
                                    INFO: Property (operatingSystemVersion) for (W2016SRV) was not set SMS_AD_SYSTEM_DISCOVERY_AGENT
                                    ERROR: System W2016SRV is a unsupported operating system, unsupported version, or malformed AD entry. Reported system type is: (). SMS_AD_SYSTEM_DISCOVERY_AGENT
                                    INFO: successfully completed directory search SMS_AD_SYSTEM_DISCOVERY_AGENT 10/14/2016 8:33:04 PM

                                    Jean

                                    3 votes
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Client OS Bit-Depth via Discovery Data

                                      Minor tweak. I would like to see Client OS Bit-Depth returned with Discovery Data. We have a custom deployment portal that allows the support tech to only see the software that matches the OS and bit-depth of the machine name they've entered to deploy to, but to get bit depth now, we have to wait for HINV and then use "Processor Width", we'd much rather this be Discovery Data so it's available immediately. We were able to implement a computer naming standard which segregates 32-bit and 64-bit OS'es by name but without that, it would have been more difficult to…

                                      3 votes
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        1 comment  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
                                      • On CAS imported object will be deleted by the registration on Primary Site and a new object will be created on thePrimary.

                                        CAS and Primary.
                                        Some clients try to reregister and do not manage to do this.
                                        The Clients send in the registration request the ImportedMachineIdentity out of the SMSCFG.INI, and this will be used in the Stored Procedure MP_IsClientRegistered.
                                        exec MP_IsClientRegistered ....

                                        ImportedMachineIdentity is not available in theDatabase (CAS or PRI), and registration fails. If we delete the ImportedMachineIdentity from SMSCFG.INI, can the Client register without issues.

                                        Here are the repro steps :
                                        1. Import Computer (that does not exist in DB) . DO it on CAS an based on MAC.
                                        2. Install Computer using OSD Tasksequence on Primary Site
                                        3.…

                                        3 votes
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Filter discovery based on AD Attributes

                                          Add the option to filter out objects based on attributes.
                                          examples:
                                          where "Operating System Name" -notlike "%2003" and"Operating System Name" -notlike "%5.1" and -notlike "%OSX%"
                                          where "Description" -notlike "%Physical%"
                                          Where "OrganizationalUnit" -ne "OU=Disabled Objects,DC=contoso,DC=com"

                                          it might delay the scan for each object and cause the discovery to take more time, but on the other hand make it more useful and stop discovering unwanted objects to the DB

                                          3 votes
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            0 comments  ·  Client Discovery  ·  Flag idea as inappropriate…  ·  Admin →
                                          ← Previous 1
                                          • Don't see your idea?

                                          Feedback and Knowledge Base