Microsoft

Microsoft Endpoint Configuration Manager Feedback

Suggestion box powered by UserVoice

Ideas

What features would you like to see?

All of the feedback that you share in these forums will be monitored and reviewed by the Microsoft engineering teams responsible for building Microsoft Endpoint Configuration Manager, though we canā€™t promise to reply to all posts.

Please do not use UserVoice to report product bugs or for assisted support.
If you believe you have found a product bug, please send us a bug report through the Configuration Manager Console (1806 and newer). To do this, press the šŸ™‚ button in the top right corner and choose ā€œSend a Frownā€. For more details, see https://docs.microsoft.com/en-us/sccm/core/understand/find-help.

If you require assisted support, please see https://aka.ms/cmcbsupport for more details.

Standard Disclaimer ā€“ our lawyers made us put this here ;-)
We have partnered with UserVoice, a third-party service, so you can give us feedback. Please note that the Microsoft Endpoint Configuration Manager feedback site is moderated and is a voluntary participation-based project. Please send only feature suggestions and ideas to improve Configuration Manager. Do not send any novel or patentable ideas, copyrighted materials, samples or demos. Your use of the portal and your submission is subject to the UserVoice Terms of Service & Privacy Policy, including the license terms.


  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. New-CMApplication rejects icons larger than 250x250

    New-CMApplication rejects icons larger than 250x250 and returns the warning and error below, even though the SCCM console allows icons up to 500x500.
    WARNING: The maximum size of an icon is 250px X 250px.
    New-CMApplication : Validation of input parameters failed. Cannot continue.

    30 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  PowerShell  ·  Flag idea as inappropriateā€¦  ·  Admin →
  2. Integrate LEDBAT into ConfigMgr

    LEDBAT is a Congestion Control Mechanism that's coming to Windows Server 2016/Windows 10. Successfully used by BitTorrent/Apple Software Update to reduce Bandwidth Saturation during content downloads. This would make WAN transfers of content by BITS (or any other mechanism) 'give way' to other business traffic. Would also improve Software Update scans and HW/Inv Uploads to the MP. LEDBAT makes sure that only unused bandwidth is used for the transfer.

    124 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    6 comments  ·  Content  ·  Flag idea as inappropriateā€¦  ·  Admin →
  3. Specify drive to cache data for creating task sequence media

    When creating TS media, the cache is always downloaded to the temp folder for the user creating it. Our standard server config only build 100GB OS partitions which fill quickly. My admin PC has 256GB SSD primary with 1TB data drive. My SSD is filled with applications and other items but i have lots of free space on my data drive.
    Trying to create standalone media fills the remaining space on my SSD and eventually fails. The option to choose to cache the content to my data drive would work as there is a lot more space available.

    8 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Operating System Deployment  ·  Flag idea as inappropriateā€¦  ·  Admin →
  4. CMPivot Log Search

    Extend CMPivot to be able to search log files on client systems. For instance, when the root cause of an issue is found in a windows or application log, declare the path to the log file and search for an entry to determine the scope of the issue in the environment.

    6 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    1 comment  ·  Tools  ·  Flag idea as inappropriateā€¦  ·  Admin →
  5. When Expiring Updates based on Supersedence Rules also Decline them in WSUS

    When SCCM expires updates based on the configured Supersedence Rules it only does so in SCCM, not WSUS. Additionally, SCCM does not approve updates in WSUS.
    Because of these two facts the WSUS Cleanup Wizard will never decline superseded updates. They are neither expired (as they are in SCCM) nor are their superseding updates approved (a requirement for the WSUS Cleanup Wizard). This causes a bloated Update Catalog that can cause very real client issues. There are scripts available to handle this situation but this is the last mile issue in regards to WSUS maintenance. If the product declined theā€¦

    95 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    6 comments  ·  Software Updates  ·  Flag idea as inappropriateā€¦  ·  Admin →
  6. Prevent Cache Limit from Causing Application Deployment Failure

    Once the cache has been filled all subsequent application deployments fail until the cache self-cleans. In CAS.log you see that the client is refusing to download the content because the cache, not the actual disk, is full.

    This strikes me as a non-optimal design choice if the goal is to successfully install applications. If I want to install an application I do not want it to fail because of an artificial limit that until very recently was set at the time of client install. Most of the time the cache clears in 24 hours and there's no problem but thereā€¦

    361 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    16 comments  ·  Application Management  ·  Flag idea as inappropriateā€¦  ·  Admin →
  7. Give us an option for Appx Provisioning Deployment

    ConfigMgr supports .appx deployment, but sometimes we want these on every user that signs into the machine. These machines may be on metered connections and not have a stable connection at the time to redownload the appx file. DISM lets us do this by hand and calls it provisioning. This is a long and complicated process when deploying to 1000's of machines.

    Currently SCCM pushed Windows Modern Applications can only installed into the current users profile even if the deployment is targeted at the machine.

    Can we get the option in SCCM for if we want the APPX provisioned forā€¦

    5 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    1 comment  ·  Application Management  ·  Flag idea as inappropriateā€¦  ·  Admin →
  8. Allow us to copy information out of the "Asset Details" pane in the Deployment Status screen

    Currently the Asset Details window in the Deployment Status screen is a good overview of what is going on with any given deployment. However, many times assets in the Error or Unknown tabs require additional steps from us. I'd like to propose that the ability to copy information from the Asset Details window (much like Ctrl+C on a collection) is added to the Configuration Manager console.

    This would allow us to automate many actions with scripts and provide quick reports without having to write custom queries

    65 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    9 comments  ·  Deployment Monitoring  ·  Flag idea as inappropriateā€¦  ·  Admin →
  9. RBA Viewer that works with CM CB

    The RBA Viewer that is released in 2015 constantly crashes in my production system. I was able to get it to work in a lab running an older verison of SCCM.

    So far it crashes with CM1606 and 1702

    Can RBA Viewer be updated to support the new permissions that have been introduced over the past 2 years and updated it with every release of CM CB?

    If there are no plans to update rbaviewer can a statement be released that the current version is not supported with CM1606 and beyond?
    Or whatever version you feel is appropriate?
    I

    32 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    6 comments  ·  Tools  ·  Flag idea as inappropriateā€¦  ·  Admin →
  10. In Windows PE booting from Iso "Configure network settings" greyed out

    When we are deploying a OS over a SCCM Boot Media Iso there is a possibility to define a IP, Gateway, Subnet ... If there is a tipping error the TS will fail and we have the possibility to push the previous button. In this Case the "Configure network settings" button is greyed out. Would be great if we could modify this settings

    10 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    1 comment  ·  Operating System Deployment  ·  Flag idea as inappropriateā€¦  ·  Admin →
  11. Stop unnecessary "New software is available" pop-up on each logon after a user has uninstalled an available application.

    After a user installs an application that was deployed as "Available", but later uninstalls the application, the user gets a balloon pop-up every time they logon saying "New software is available".

    There is NO way to prevent this from happening apart from removing the user from the collection where the application was deployed, and adding them back. This has been the case since CM12 was released but this is not a desirable behavior especially when there's no "valid" way of preventing this.

    348 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    22 comments  ·  Software Center  ·  Flag idea as inappropriateā€¦  ·  Admin →
  12. Allow Client Notification actions to be triggered from the Devices node.

    Please allow Client Notification actions to be triggered from the Devices node. You currently can only do this from Device Collections.

    35 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    completed  ·  4 comments  ·  Collections  ·  Flag idea as inappropriateā€¦  ·  Admin →
  13. Add Reboot Count functionality to the Disable BitLocker TS Step

    Newer versions of the BitLocker management tools (specifically manage-bde) now support the ability to suspend the BitLocker protection for defined number of reboots. The current Disable BitLocker TS step only suspends BitLocker for 1 reboot. There are cases that having a defined number of reboots (or indefinitely until re-enabled at the end of a TS) can come in handy (flashing the BIOS, MBR2GPT, In-place Upgrade with PINs, etc.).

    Please add this functionality to the Disable BitLocker TS step for the operating systems that support it.

    122 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    3 comments  ·  Operating System Deployment  ·  Flag idea as inappropriateā€¦  ·  Admin →
  14. Create an OSD variable for Secure Boot - _SMSTSSecureBootState

    Create an OSD variable for Secure Boot called _SMSTSSecureBootState. It should have three values depending on the state and the currently running OS: Enabled, Disabled, NA. This can be used during a TS to determine if Secure Boot should be enabled. Currently, a TS variable has to be defined and set based on if the registry key exists or not.

    82 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    1 comment  ·  Operating System Deployment  ·  Flag idea as inappropriateā€¦  ·  Admin →

    Updating status to complete.

    The opt-in phase of our 2002 release (fast ring) is now live and contains the changes asked for with this item – the new read-only variable _TSSecureBoot
    You can opt-in and then download 2002 through their Admin Console now.

    Blog: https://techcommunity.microsoft.com/t5/configuration-manager-blog/update-2002-for-microsoft-endpoint-configuration-manager-current/ba-p/1272670
    Docs: https://docs.microsoft.com/configmgr/core/plan-design/changes/whats-new-in-version-2002
    Support Information: https://aka.ms/cmcssreleaseinfo

  15. Set-CM<Type>DeploymentType fails with Invalid Property when updating Content Location

    Since I updated to 1706, any of the Set-CM<Type>DeploymentType cmdlets fail with an error when I try to update the content path/location to another location. Based on the error message, it seems the cmdlets need to have extra parameters added to handle the separate Install and Uninstall content paths/locations. Perhaps you could add -UninstallContentLocation and a switch for -UninstallContentSameAsInstallContent.

    Set-CMScriptDeploymentType : Invalid property: object Application(ScopeId8C35D19A-F107-4878-83CC-9E26B213220D:Applicationa463d8c5-c106-43ae-993b-f5bcb2f4ae4c:15) property
    DeploymentTypes.DeploymentTypes[0].Installer.Installer.UninstallContent: Uninstall Content not found in Contents collection
    At line:54 char:3
    + Set-CMScriptDeploymentType -ApplicationName $cmApplicationNa ...
    + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    + CategoryInfo          : NotSpecified: (:) [Set-CMScriptDeploymentType], InvalidPropertyException
    
    + FullyQualifiedErrorId : Microsoft.ConfigurationManagement.ApplicationManagement.InvalidPropertyException,Microsoft.ConfigurationManagement.Cmdlets.AppMan.Commands.SetScriptDeploymentTypeCommand

    9 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    7 comments  ·  PowerShell  ·  Flag idea as inappropriateā€¦  ·  Admin →
  16. Change the maximum run time of cumulative updates to 30 minutes

    With the new 'cumulative updates' model I think it would be a good idea to change the maximum run time of cumulative updates to 30 minutes (or whatever is best suited). I have noticed more timeout issues with patching in the last couple of months due to the default 10 minutes not being enough time to install 'X' patches as a single CU. This would be preferred to manually overriding them every month.

    298 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    35 comments  ·  Software Updates  ·  Flag idea as inappropriateā€¦  ·  Admin →
  17. Add Windows 10 Build Subversion "UBR" collection to the default HINV classes

    The UBR registry key is responsible for displaying the subversion of a Windows 10 build to the end-user. For example 14393. where is the UBR string. If this is added to the HINV list of default classes this will allow for administrators to retrieve this information!

    This is located in: HKEYLOCALMACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion

    UBR REG_DWORD

    This will help administrators differentiate what intermediate builds of Windows 10 they have install and also support patch management because they can easily compare the released patches to the subversion build each month.

    60 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    12 comments  ·  Client Discovery  ·  Flag idea as inappropriateā€¦  ·  Admin →
  18. Offline Servicing - Select Indexes to Update

    At the moment, when you do Offline Image Servicing on a Server WIM - it applies it to all image indexes (Standard, Standard Core, Datacenter, Datacenter Core, etc...)

    Can we have an option to select which index (or indexes) we would like to service?

    If someone only deploys Standard (gui) and never Datancentre, they don't really need to patch it..

    It would also save some time

    32 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    5 comments  ·  Operating System Deployment  ·  Flag idea as inappropriateā€¦  ·  Admin →

    Thanks for all your suggestions and feedback, updating status to completed.
    The Add Operating System Import wizard now has an option for selecting the index to import.

    SCCM 1902 fast Ring released today
    Blog: https://techcommunity.microsoft.com/t5/Configuration-Manager-Blog/Update-1902-for-Configuration-Manager-current-branch-is-now/ba-p/376516
    Docs: https://docs.microsoft.com/sccm/core/plan-design/changes/whats-new-in-version-1902

  19. Stop CMTrace from asking us if we want to use it as the default viewer for log files in WinPE

    Please add the following registry keys to WinPE whenever a Boot Image is created/updated to prevent it from asking every time if we want to use CMTrace as the default viewer for log files:

    Reg add HKU\Software\Classes.lo_ /ve /d Log.File /f

    Reg add HKU\Software\Classes.log /ve /d Log.File /f

    Reg add HKU\Software\Classes\Log.File\shell\open\command /ve /d "&quot;x:\sms\bin\i386\CMTrace.exe&quot; &quot;%%1&quot;" /f

    See more here: https://miketerrill.net/2017/05/13/how-to-open-cmtrace-in-winpe-like-a-boss/

    51 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    2 comments  ·  Operating System Deployment  ·  Flag idea as inappropriateā€¦  ·  Admin →

    Updating status to completed

    This is available in our 1802 release, details below

    General Blog: https://cloudblogs.microsoft.com/enterprisemobility/?p=69422

    Docs: https://docs.microsoft.com/en-us/sccm/core/plan-design/changes/whats-new-in-version-1802

    One question I’ve been asked a few times is ‘can I take the copy of CMTrace from the Tech Preview build and use it with my version of SCCM?’ – answer is Yes.

  20. Allow all Admin Console access to require MFA

    Make everything more secure by requiring Multi-Factor auth for console access. Bonus: make it work over the internet securely.

    38 votes
    Vote
    Sign in
    (thinkingā€¦)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    7 comments  ·  Admin Console  ·  Flag idea as inappropriateā€¦  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base