Microsoft

System Center Configuration Manager Feedback

Suggestion box powered by UserVoice

Ideas

What features would you like to see?

All of the feedback that you share in these forums will be monitored and reviewed by the Microsoft engineering teams responsible for building System Center Configuration Manager, though we can’t promise to reply to all posts.

Please do not use UserVoice to report product bugs or for assisted support.
If you believe you have found a product bug, please send us a bug report through the Configuration Manager Console (1806 and newer). To do this, press the 🙂 button in the top right corner and choose “Send a Frown”. For more details, see https://docs.microsoft.com/en-us/sccm/core/understand/find-help.

If you require assisted support, please see https://aka.ms/cmcbsupport for more details.

Standard Disclaimer – our lawyers made us put this here ;-)
We have partnered with UserVoice, a third-party service, so you can give us feedback. Please note that the System Center Configuration Manager feedback site is moderated and is a voluntary participation-based project. Please send only feature suggestions and ideas to improve Microsoft Configuration Manager. Do not send any novel or patentable ideas, copyrighted materials, samples or demos. Your use of the portal and your submission is subject to the UserVoice Terms of Service & Privacy Policy, including the license terms.

How can we improve Configuration Manager?

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Automatically Publish Full Content for Third Party Software Updates

    With the release of CB 1806 we are now able to publish third party updates using custom catalogs. Ideally, third party patches would function exactly like first party patches from an administration and automation perspective. Currently there's two main areas where this is not the case.

    Synchronization Schedule:
    I could be wrong on this but I believe that subscribed catalogs sync automatically every 24-hours. While that's nice, it would be great to simply integrate with the existing sync schedule. Sync the catalogs, publish relevant metadata to WSUS, then sync the SUP(s).

    Automatic Deployment Rules:
    Currently, only update metadata is published…

    248 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    12 comments  ·  Software Updates  ·  Flag idea as inappropriate…  ·  Admin →
  2. Integrate Microsoft LAPS Functionality

    The Microsoft Local Admin Password Solution (LAPS) is great because of the security it provides, but is not in widespread use because it isn't enabled by default and requires desktop/server teams to work together to implement.

    Integrate the functionality of Microsoft LAPS into the ConfigMgr infrastructure.

    This could include simple steps to control replace the group policy need with a new compliance item node, or could include completely supplanting of the functionality (similar to how MBAM makes it so you don't need AD for managing BitLocker recovery keys).

    Anything that ConfigMgr can do to bring down the bar for securing…

    234 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    12 comments  ·  Setup and Server Infrastructure  ·  Flag idea as inappropriate…  ·  Admin →
  3. Deploy Package to Multiple Collections at one time

    Allow packages to be deployed to multiple collections at one time. For instance I need AppX to go to Lab 1, Lab 2 and Lab4. Instead of going into AppX 3 different times to deploy, it would be nice to deploy it to all 3 labs at one time.

    232 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    Noted  ·  15 comments  ·  Application Management  ·  Flag idea as inappropriate…  ·  Admin →
  4. Have the ability to remove a CAS when only one primary site is left

    Beginning with 2012SP1, we have the ability to add a CAS to an autonomous primary site. It could be interesting to reverse the proposition by having the ability to remove a CAS above a Primary when a CAS is no longer needed or has been set for a wrong reason.
    I know that it could be done through creating another hierarchy and using migration tasks by this is quite difficult for it requires additional hardware.

    225 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    Noted  ·  16 comments  ·  Setup and Server Infrastructure  ·  Flag idea as inappropriate…  ·  Admin →
  5. ADR New Search Criteria, Deployed = yes/no

    I propose a new search criteria for ADR, to avoid multiple deployments for a single update. This is a pain to clean up afterwards.

    220 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    12 comments  ·  Software Updates  ·  Flag idea as inappropriate…  ·  Admin →
  6. Apply all deployed applications step in OSD

    A step during OSD that queries SCCM for the applications deployed to a machine. If any are deployed to collections the machine is a member of they are installed one at a time, performing any restarts untill the whole list is complete. This should be an integrated step rather than implemented inconsistently by third-parties in PS or IIS

    210 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    Noted  ·  7 comments  ·  Operating System Deployment  ·  Flag idea as inappropriate…  ·  Admin →
  7. When a console crashes and you are editing a task sequence, allow sedo unlock if user name matches yours

    It happened to me yesterday with SCCM 1602 CB, I was editing two task sequences at the same time, trying to copy a section from one into the other when the console crashed. I needed the work done and this didn't help as as soon as I started the console again I got the familiar message shown below. The problem is you have to wait 30 minutes for the sedo lock to be removed or use PowerShell cmdlets to try and remove the lock.

    I don't think that is necessary at all as there is already a retry button on…

    209 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    planned  ·  10 comments  ·  Admin Console  ·  Flag idea as inappropriate…  ·  Admin →
  8. ADR Available Deployments

    I would like to see ADR's support the creation of Available deployments in addition to Required deployments. We have some business cases where a certain subset of servers are aren't allowed to "push" software updates to until the server/app owners have verified the patches.

    The issue is that these servers don't have connectivity to the internet so we have to deliver them via ConfigMgr. By creating an Available update using an ADR, it streamlines our ability to "deliver" the updates to all systems, and allow the Patching Team, or App/Server owner to patch according to their own business schedules.

    205 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    19 comments  ·  Software Updates  ·  Flag idea as inappropriate…  ·  Admin →
  9. Allow us the ability to view all variables and their values that are available in a task sequence (both built-in and custom) via a gui

    While testing some new functionality in SCCM 1602 current branch I inadvertently searched for a possible new variable using the 'set dynamic variable' step.

    Unfortunately that doesn't list read only variables in the 'existing variables' list (read only variables begin with _). It would be awesome if this gui would list all built-in variables (including read-only ones) as this would make searching for a particular variable easier than having to google or bing it.

    Secondly, how about the option to list all custom defined variables in this gui, along with their values (if any). today we get the following headings…

    194 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Operating System Deployment  ·  Flag idea as inappropriate…  ·  Admin →
    Noted  ·  sangeev responded

    Thanks for the feedback.

    Updated by bobmn for sangeev/OSD

  10. Improve Content Replication

    Content Replication from Site to DPs should be a frustration free Process or SCCM Admins. Unfortunately, I know no customer without smaller or bigger issues in this area.
    Here is an uncomplete list of some issues I´ve noticed:
    • Content Eval - Scheduled Task lost
    o SCCM does not check if the schedule task got lost/deleted
    o Suggested Solution: SCCM should verify the Scheduled Task on Service Startup
    • Content Eval - Hash mismatch/Eval fails for package
    o When content Eval fails for a package, the admin must manually redistribute it / take care of the error
    o There should…

    193 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    Noted  ·  2 comments  ·  Content  ·  Flag idea as inappropriate…  ·  Admin →
  11. Make automatic client upgrade more intelligent to not break other running installations

    Right now, the automatic Client upgrade scheduled Task is not aware of any running installations. So if appenforce.log shows a running Installation and at the same time the randomly timed scheduled tasks kicks in, the Installation cannot finish without error and will randomly leave the Installation or the SCCM Client itself in a unhealthy state. A reinstallation is the only way out.

    Repro steps
    - Activate automatic Client Upgrade in Hierarchy settings
    - Exclude some test clients from automatic client upgrade
    - Create an Application with a deploymenttype using a custom script
    - As the script, use a batch file…

    189 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    5 comments  ·  Client Deployment  ·  Flag idea as inappropriate…  ·  Admin →
  12. Windows 10 Servicing Customization

    It would be great to be able to customize the Windows 10 image or allow a "clean up script" to run post install. I like the concept of the Windows 10 Servicing part of the SCCM console. I think it will become important as upgrades start rolling out 1-2 times a year and majority of companies have Windows 10 clients that need servicing. Being able to create Servicing plans will help keep IT on top of the upgrade process through different updates.

    The current model just doesn't work for a lot of companies. Not many places allow games such as…

    185 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    10 comments  ·  Operating System Deployment  ·  Flag idea as inappropriate…  ·  Admin →
  13. F8 Troubleshooting Environment Steroids (F8TES)

    Replace the OSD Boot Image "Enable CMD Support (testing only)" feature with something that is more robust, helpful, and useful outside of testing like the F8 Troubleshooting Environment Steroids (F8TES).

    Info: Display full name of task sequence and its ID
    Info: Display full name of TS Deployment and its ID
    Info: Display full name and type of error step
    Info: Display error code
    Info: (Stretch Goal) Display useful error message for top 10 errors

    Button: “Open Command Prompt”
    - Launches the command prompt
    - Defaults to Insert instead of Overwrite (it currently defaults to overwrite in the WinPE phase)

    Button:…

    186 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    13 comments  ·  Operating System Deployment  ·  Flag idea as inappropriate…  ·  Admin →

    Updating status to planned.

    We shipped our 1905 Technical Preview today.

    Doc: https://docs.microsoft.com/sccm/core/get-started/2019/technical-preview-1905
    Blog: https://techcommunity.microsoft.com/t5/Configuration-Manager-Blog/Group-applications-into-a-single-deployment-in-ConfigMgr/ba-p/624318

    This preview contains the first release of the task sequence debugger. We’ll continue working on it to address more of the asks in this item.

  14. Windows 10 Servicing Dashboard: Make it clickable

    When I go to the Windows 10 Servicing Dashboard, I got a nice PieChart of the Windows 10 Clients and their Version.
    But when I click on the PieChart, nothing happens. It would be great to have the same experience on this Dashboard like on the SCEP Dashboards.
    That means, if I click on the PieChart one of the Windows 10 Version, a new collection would be opened, with the corresponding Devices.

    185 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    7 comments  ·  Software Updates  ·  Flag idea as inappropriate…  ·  Admin →
  15. Would like to replace the Windows defender icon with the SCEP icon when managed by Endpoint Protection

    In windows 10 when managed by SCCM+Endpoint Protection, we get Windows Defender as the Endpoint Protection client, which is fine as they use the same engine.

    However the icon is for Windows Defender which doesn't make sense.

    Can we change it to the SCEP icon instead which would make more sense and go along with the installed software SCEP in control panel which does have the correct icon (in Programs and Features).

    Having the SCEP icon would be a nice visual clue (aside from looking at applied policies) that SCEP was managing Antivirus rather than Windows itself

    183 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    1 comment  ·  Endpoint Protection  ·  Flag idea as inappropriate…  ·  Admin →
  16. Show Machines within Console that Require Updates

    You know that "x" number of machines require this update. Would you please list the machines names below. Screenshot for what I would like.

    177 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    6 comments  ·  Software Updates  ·  Flag idea as inappropriate…  ·  Admin →
  17. Speed up OSD by having ConfigMgr set High Performance power settings in WinPE and Running OS during TS

    When you run a task sequence, both WinPE and the target OS by default run with a Balanced power plan. Changing this in both WinPE and the target OS can significantly speed up the task sequence. For example, when applying a large WIM file, we've seen laptops go from taking 15 minutes to apply to less than 8 minutes by adding some Run Command Line steps to change the power to High Performance.

    170 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    8 comments  ·  Operating System Deployment  ·  Flag idea as inappropriate…  ·  Admin →
  18. DSC to replace or compliment basline feature

    DSC is a wonderful framework for handling baseline configurations across Windows and Linux machines, but it's completely unsupported in SCCM directly. While a Pull server is certainly more simplistic than an SCCM hierarchy, it would still be very beneficial to have some integration in a couple of areas:

    Management Points can easily be configured to host mof configurations for clients, and a new client policy class for allowing the SCCM agent to configure the pull server settings on a host would be great. Alternatively a new role could be made ... not sure that would feel as elegant.

    The baseline…

    167 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Compliance Settings  ·  Flag idea as inappropriate…  ·  Admin →
  19. Allow deployments using application model to be installed from DP rather than downloaded to ccmcache folder

    I have to create several very large (10GB and up) software deployments each year and install them for two thirds of the user base. Preferred method of delivery is install directly from the DP rather than download the installation files to C:\windows\ccmcache. It would be nice to do this using the application model so I can make use of the extended feature set it provides over the package model. I have to work around the limitations using convoluted wrapper scripts to get everything working properly.

    167 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    Noted  ·  18 comments  ·  Application Management  ·  Flag idea as inappropriate…  ·  Admin →
  20. add possibility to logoff user for Software Installation and prevent login during installation.

    It would be great to have a possibility to create a deployment where the User would be logged off during the installation of Software. Useful for Software like Java Runtime or Adobe Pro where a running application can prevent the installation.
    The User should be informed that an installation will be started and he will be logged off. The User should be not able to login during the installation.

    162 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: facebook google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    Noted  ·  9 comments  ·  Application Management  ·  Flag idea as inappropriate…  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base