<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The Mobile Device Manager Support Team Blog : CM</title><link>http://blogs.technet.com/mdm/archive/tags/CM/default.aspx</link><description>Tags: CM</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Solution: The Group Policy setting “Block unsigned theme installation” for System Center Mobile Device Manager 2008 is not correctly applied to Windows Mobile 6.1 mobile devices</title><link>http://blogs.technet.com/mdm/archive/2009/03/11/solution-the-group-policy-setting-block-unsigned-theme-installation-for-system-center-mobile-device-manager-2008-is-not-correctly-applied-to-windows-mobile-6-1-mobile-devices.aspx</link><pubDate>Wed, 11 Mar 2009 18:06:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3211679</guid><dc:creator>jchornbe</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/mdm/comments/3211679.aspx</comments><wfw:commentRss>http://blogs.technet.com/mdm/commentrss.aspx?PostID=3211679</wfw:commentRss><description>&lt;p&gt;&lt;a href="http://technet.microsoft.com/en-us/scmdm/default.aspx" target="_blank"&gt;&lt;img height="91" alt="image" src="http://blogs.technet.com/blogfiles/configurationmgr/WindowsLiveWriter/Configmgr2007CalltoHttpSendRequestSyncfa_7516/image_thumb_1.png" width="93" align="left" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Just a quick FYI on an issue we came across recently.&amp;#160; This should be a Knowledge Base article soon but I figured I’d post it here first to give all you faithful readers first notice.&amp;#160; If you’re trying to use the Group Policy setting “Block unsigned theme installation” for System Center Mobile Device Manager 2008 and it’s not working correctly then this one’s for you: &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Issue:&lt;/u&gt;&lt;/strong&gt; When you Enable the Group Policy setting &lt;strong&gt;&lt;em&gt;Block unsigned theme installation &lt;/em&gt;&lt;/strong&gt;by using Microsoft System Center Mobile Device Manger (MDM) 2008 Group Policy management functionality, some Windows Mobile 6.1 mobile devices may not allow the installation of default built-in themes.&lt;/p&gt;  &lt;p&gt;When you Disable the Group Policy setting &lt;strong&gt;&lt;em&gt;Block unsigned theme installation&lt;/em&gt;&lt;/strong&gt; by using Microsoft System Center Mobile Device Manger (MDM) 2008 Group Policy management functionality, some Windows Mobile 6.1 mobile devices may continue to block the installation of unsigned themes. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Cause:&lt;/u&gt;&lt;/strong&gt; This group policy setting affects Windows Mobile Security Policy 4103 SECPOLICY_UNSIGNEDTHEMES when applied to the device. The default value for this policy is SECROLE_USER_UNAUTH, however when the group policy setting is set to Disable the value SECROLE_USER_AUTH is applied.&lt;/p&gt;  &lt;p&gt;When this policy is set to Enable the value SECROLE_NONE is applied. Theme files as well as other cab files do not receive special permissions as executable files do, even if they are placed in-rom, so this policy continues to affect these default theme files and blocks their installation.&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Note: SECROLE_USER_UNAUTH corresponds to the decimal value 64, and SECROLE_USER_AUTH corresponds to 16.&lt;/em&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Workaround:&lt;/u&gt;&lt;/strong&gt; To work around the behavior when set to Enable, you must sign the default theme files you want to enable users to install. To work around the behavior when set to Disable follow the procedures below:&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Important: The following workaround applies only to the English version of Microsoft System Center Mobile Device Manger 2008. There are no workarounds for other language versions of the product at this time.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Warning: Serious problems might occur if you modify system files incorrectly. These problems might require that you reinstall server software or components of server software. Microsoft cannot guarantee that these problems can be solved. Modify the system files at your own risk.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Important: The following workaround requires you to modify an important system file. Make sure that you back up the referenced file before you modify it. Make sure that you know how to restore the system file if a problem occurs. Do not proceed with the following procedure if you do not know how to back up and restore a file. Revert to the original file if you encounter any problems with the workaround.&lt;/em&gt; &lt;/p&gt;  &lt;p&gt;The following steps modify the ADM template file that includes the &lt;strong&gt;&lt;em&gt;Block unsigned theme installation&lt;/em&gt;&lt;/strong&gt; Group Policy setting. When you have successfully modified the file, you can use the Block unsigned theme installation Group Policy setting to correctly update managed devices.&lt;/p&gt;  &lt;p&gt;1.&amp;#160;&amp;#160;&amp;#160; On the computer on which you have installed the MDM Administrator Tools, navigate to the %windir%\INF folder.    &lt;br /&gt;2.&amp;#160;&amp;#160;&amp;#160; Type the following at a command prompt to make a backup copy of the mobile.adm file:&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color="#004080"&gt;copy mobile.adm mobile.adm.bak&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;3.&amp;#160;&amp;#160;&amp;#160; In a text editor, such as Notepad, edit the mobile.adm file to change the VALUEOFF setting for Policy_BlockUnsignedThemes &lt;/p&gt;  &lt;p&gt;Replace this: &lt;/p&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; POLICY !!Policy_BlockUnsignedThemes      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; EXPLAIN !!Explain_BlockUnsignedThemes       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; VALUENAME &amp;quot;4103&amp;quot;       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; VALUEON NUMERIC 0       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; VALUEOFF NUMERIC 16       &lt;br /&gt;END POLICY&lt;/font&gt; &lt;/p&gt;  &lt;p&gt;with this: &lt;/p&gt;  &lt;p&gt;&lt;font color="#0000ff"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; POLICY !!Policy_BlockUnsignedThemes      &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; EXPLAIN !!Explain_BlockUnsignedThemes       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; VALUENAME &amp;quot;4103&amp;quot;       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; VALUEON NUMERIC 0       &lt;br /&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; VALUEOFF NUMERIC 64       &lt;br /&gt;END POLICY&lt;/font&gt; &lt;/p&gt;  &lt;p&gt;4.&amp;#160;&amp;#160;&amp;#160; Save the file and exit the text editor. &lt;/p&gt;  &lt;p&gt;To apply the new setting to managed devices, you must update the &lt;strong&gt;&lt;em&gt;Block unsigned theme installation&lt;/em&gt;&lt;/strong&gt; Group Policy setting in MDM. To refresh the setting in MDM, in the MDM Console run the following cmdlet: &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color="#004080"&gt;Update-MobilePolicyCalculation &amp;lt;device&amp;gt;&lt;/font&gt;&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;Where &amp;lt;device&amp;gt; is the managed device on which you want to update the Group Policy setting. New settings are pushed down to managed devices during the next synchronization with MDM. &lt;/p&gt;  &lt;p&gt;This information applies to:&lt;/p&gt;  &lt;p&gt;•&amp;#160;&amp;#160;&amp;#160; Microsoft System Center Mobile Device Manager 2008    &lt;br /&gt;•&amp;#160;&amp;#160;&amp;#160; Microsoft Windows Mobile 6.1 mobile devices&lt;/p&gt;  &lt;p&gt;Hope this helps,&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;J.C. Hornbeck | Manageability Knowledge Engineer&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3211679" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mdm/archive/tags/Troubleshoot/default.aspx">Troubleshoot</category><category domain="http://blogs.technet.com/mdm/archive/tags/CM/default.aspx">CM</category><category domain="http://blogs.technet.com/mdm/archive/tags/KB+Article/default.aspx">KB Article</category><category domain="http://blogs.technet.com/mdm/archive/tags/Group+Policy/default.aspx">Group Policy</category></item><item><title>Collecting large amount of device inventory information during OMA session causes MDM server to timeout</title><link>http://blogs.technet.com/mdm/archive/2009/01/08/collecting-large-amount-of-device-inventory-information-during-oma-session-causes-mdm-server-to-timeout.aspx</link><pubDate>Thu, 08 Jan 2009 16:38:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3178140</guid><dc:creator>jchornbe</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mdm/comments/3178140.aspx</comments><wfw:commentRss>http://blogs.technet.com/mdm/commentrss.aspx?PostID=3178140</wfw:commentRss><description>&lt;p&gt;Here's an issue we run into every now and then so I thought it might be worth a mention here.&amp;#160; If you're noticing GP and software distribution delivery failures then this may be your issue:&lt;/p&gt;  &lt;p&gt;========&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Issue:&lt;/u&gt;&lt;/strong&gt; Collecting large amount of device inventory information during an Open Mobile Alliance (OMA) session may cause the System Center Mobile Device Manager server to timeout. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Cause:&lt;/u&gt;&lt;/strong&gt; During the first OMA session on some devices, if the device is instructed by the server to collect a large amount of inventory information it might result in the session taking up to 20 minutes to complete or it may timeout completely depending on the timeout settings on the server. This delay results from the time taken by the device to retrieve and process inventory information that the server requested.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Resolution: &lt;/u&gt;&lt;/strong&gt;To resolve this problem, restore the default inventory collection set using the &lt;strong&gt;&lt;em&gt;Restore-MDMInventoryDefaults&lt;/em&gt;&lt;/strong&gt; cmdlet or remove items from the inventory collection using &lt;strong&gt;&lt;em&gt;Set-MDMInventoryItem&lt;/em&gt;&lt;/strong&gt; cmdlet. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Additional Information:&lt;/u&gt;&lt;/strong&gt; In this scenario the device user will notice Group Policy and software distribution delivery failure.&amp;#160; The server administrator may also notice two messages in system logs:&lt;/p&gt;  &lt;p&gt;&lt;em&gt;The management session with device xxx (device SID is displayed here not device ID) was not completed. The connection may have been lost, or the session timed out due to inactivity.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;and&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Erroneous OMA DM message received from device xxx&amp;#160; (device SID is displayed here not device ID) during management session.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;========&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;J.C. Hornbeck | Manageability Knowledge Engineer&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3178140" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mdm/archive/tags/Troubleshoot/default.aspx">Troubleshoot</category><category domain="http://blogs.technet.com/mdm/archive/tags/Error/default.aspx">Error</category><category domain="http://blogs.technet.com/mdm/archive/tags/SP1/default.aspx">SP1</category><category domain="http://blogs.technet.com/mdm/archive/tags/CM/default.aspx">CM</category></item><item><title>SCMDM: Enrollment fails with "Unknown error in Enrollment service: System.ArgumentNullException: Value cannot be null"</title><link>http://blogs.technet.com/mdm/archive/2009/01/05/scmdm-enrollment-fails-with-unknown-error-in-enrollment-service-system-argumentnullexception-value-cannot-be-null.aspx</link><pubDate>Mon, 05 Jan 2009 17:29:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3176553</guid><dc:creator>jchornbe</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mdm/comments/3176553.aspx</comments><wfw:commentRss>http://blogs.technet.com/mdm/commentrss.aspx?PostID=3176553</wfw:commentRss><description>&lt;P&gt;Here's another MDM enrollment failure issue we ran across recently that's caused by the CA not being available when the SCMDM Enrollment Service starts.&amp;nbsp; Fortunately the solution to this one is pretty easy:&lt;/P&gt;
&lt;P&gt;========&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Issue:&lt;/U&gt;&lt;/STRONG&gt; Enrollment fails and the following event is logged on the Enrollment Server:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color=#004080&gt;Unknown error in Enrollment service: &lt;BR&gt;System.ArgumentNullException: Value cannot be null. &lt;BR&gt;Parameter name: data &lt;BR&gt;&amp;nbsp;&amp;nbsp; at Microsoft.Mobile.ManagementServices.EnrollmentServer.CryptoService.ComputeHmac(Byte[] data, Byte[] sessionKey) &lt;BR&gt;&amp;nbsp;&amp;nbsp; at Microsoft.Mobile.ManagementServices.EnrollmentServer.Authentication.AuthenticateServer(BootstrappingRequest rc) &lt;BR&gt;&amp;nbsp;&amp;nbsp; at Microsoft.Mobile.ManagementServices.EnrollmentServer.Authentication.Authenticate(RequestContext rc)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Cause:&lt;/U&gt;&lt;/STRONG&gt; This can occur if the Certificate Authority (CA) was not running when the SCMDM Enrollment Service started. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Resolution:&lt;/U&gt;&lt;/STRONG&gt; Restart the SCMDM Enrollment Service. &lt;/P&gt;
&lt;P&gt;========&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;J.C. Hornbeck | Manageability Knowledge Engineer&lt;/STRONG&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3176553" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mdm/archive/tags/Troubleshoot/default.aspx">Troubleshoot</category><category domain="http://blogs.technet.com/mdm/archive/tags/Error/default.aspx">Error</category><category domain="http://blogs.technet.com/mdm/archive/tags/SP1/default.aspx">SP1</category><category domain="http://blogs.technet.com/mdm/archive/tags/CM/default.aspx">CM</category><category domain="http://blogs.technet.com/mdm/archive/tags/Enrollment/default.aspx">Enrollment</category></item><item><title>SCMDM: Mobile Device Manager setup error: "Failed to determine status of MDM databases on SQL instance"</title><link>http://blogs.technet.com/mdm/archive/2008/12/18/scmdm-mobile-device-manager-setup-error-failed-to-determine-status-of-mdm-databases-on-sql-instance.aspx</link><pubDate>Thu, 18 Dec 2008 19:28:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3170873</guid><dc:creator>jchornbe</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mdm/comments/3170873.aspx</comments><wfw:commentRss>http://blogs.technet.com/mdm/commentrss.aspx?PostID=3170873</wfw:commentRss><description>&lt;P&gt;Here's one more MDM Service Pack 1 issue for you, this one involving a setup error you might run into when upgrading:&lt;/P&gt;
&lt;P&gt;========&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Issue:&lt;/U&gt;&lt;/STRONG&gt; Upgrading to System Center Mobile Device Manager 2008 SP1 fails with the following message: &lt;/P&gt;
&lt;P&gt;Failed to determine status of MDM databases on SQL instance '&amp;lt;instance_name&amp;gt;'. Setup will now roll back all changes &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Cause:&lt;/U&gt;&lt;/STRONG&gt; During the upgrade, System Center Mobile Device Manager 2008 SP1 does not have access to the DB_USER and DB_PWD properties provided in previous installations of Device Management Servers or Enrollment Servers. It will instead default to using the current windows user's credentials. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Resolution:&lt;/U&gt;&lt;/STRONG&gt; There are two ways to work around this issue: &lt;/P&gt;
&lt;P&gt;1. Use Windows integrated authentication instead of the SQL username and password. The user who performs the upgrade must have sufficient privileges on the SQL Server where the MDM databases reside. &lt;/P&gt;
&lt;P&gt;or &lt;/P&gt;
&lt;P&gt;2. Uninstall your existing version of MDM prior to installing the SP1 version. Do not remove the existing databases during the uninstall process or your data will be lost. Once MDM is uninstalled, install System Center Mobile Device Manager 2008 SP1. It will give you the option to use the databases from your previous installation of MDM. &lt;/P&gt;
&lt;P&gt;========&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;J.C. Hornbeck | Manageability Knowledge Engineer&lt;/STRONG&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3170873" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mdm/archive/tags/Troubleshoot/default.aspx">Troubleshoot</category><category domain="http://blogs.technet.com/mdm/archive/tags/SP1/default.aspx">SP1</category><category domain="http://blogs.technet.com/mdm/archive/tags/CM/default.aspx">CM</category></item><item><title>SCMDM: Enrollment fails if a port other than 443 is used for the Enrollment Service</title><link>http://blogs.technet.com/mdm/archive/2008/12/17/scmdm-enrollment-fails-if-a-port-other-than-443-is-used-for-the-enrollment-service.aspx</link><pubDate>Wed, 17 Dec 2008 16:45:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3170269</guid><dc:creator>jchornbe</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mdm/comments/3170269.aspx</comments><wfw:commentRss>http://blogs.technet.com/mdm/commentrss.aspx?PostID=3170269</wfw:commentRss><description>&lt;p&gt;Here's another SP1 issue that we came across.&amp;#160; If your server and client logs indicate that Enrollment failed because it could not resolve the Enrollment server URL and you changed the port then this may be your issue:&lt;/p&gt;  &lt;p&gt;========&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Issue:&lt;/u&gt;&lt;/strong&gt; The server and client logs indicate that enrollment failed because it could not resolve the enrollment server URL. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Cause:&lt;/u&gt;&lt;/strong&gt; Enrollment can fail if PAT (Port Address Translation) is used or if an alternate port other than 443 is used for the Enrollment Service. &lt;/p&gt;  &lt;p&gt;Setup itself does not allow you to specify an alternate port number for the enrollment server when it is installed, so if an alternate port is specified in IIS after installation, and the SCP value for the enrollment server is not changed, then client auto discovery breaks. What happens is that the client is sent back a request to switch to the URI of an enrollment server without the alternate port causing the enrollment to fail. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Resolution:&lt;/u&gt;&lt;/strong&gt; If the port number in IIS is changed to a port other than 443, the SCP value must also be changed. &lt;/p&gt;  &lt;p&gt;To change the SCP value follow these steps: &lt;/p&gt;  &lt;p&gt;1. Launch ADSIEDIT.MSC. &lt;/p&gt;  &lt;p&gt;2. Right click on &amp;#8220;CN=Instance&amp;#8221; to bring up the property dialog box. &lt;/p&gt;  &lt;p&gt;3. Check the &amp;#8216;Show only attributes that have values&amp;#8217; checkbox. &lt;/p&gt;  &lt;p&gt;4. Double click on &amp;#8216;keywords&amp;#8217; attribute. &lt;/p&gt;  &lt;p&gt;5. Change the &amp;#8220;enurl= &amp;#8230;&amp;#8221; value to the new port number. &lt;/p&gt;  &lt;p&gt;========&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;J.C. Hornbeck | Manageability Knowledge Engineer&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3170269" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mdm/archive/tags/Troubleshoot/default.aspx">Troubleshoot</category><category domain="http://blogs.technet.com/mdm/archive/tags/SP1/default.aspx">SP1</category><category domain="http://blogs.technet.com/mdm/archive/tags/CM/default.aspx">CM</category><category domain="http://blogs.technet.com/mdm/archive/tags/Enrollment/default.aspx">Enrollment</category></item><item><title>SCMDM: Set-EnrollmentPermissions returns "Error encountered when delegating container..."</title><link>http://blogs.technet.com/mdm/archive/2008/12/16/scmdm-set-enrollmentpermissions-returns-error-encountered-when-delegating-container.aspx</link><pubDate>Tue, 16 Dec 2008 18:51:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3169742</guid><dc:creator>jchornbe</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mdm/comments/3169742.aspx</comments><wfw:commentRss>http://blogs.technet.com/mdm/commentrss.aspx?PostID=3169742</wfw:commentRss><description>&lt;P&gt;Here's another MDM SP1 issue for you.&amp;nbsp; This one involves the &lt;STRONG&gt;Set-EnrollmentPermissions&lt;/STRONG&gt; command and an error you can receive if SCMDMEnrollmentServers has full permissions on the specified OU:&lt;/P&gt;
&lt;P&gt;========&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Issue:&lt;/U&gt;&lt;/STRONG&gt; When running the &lt;STRONG&gt;Set-EnrollmentPermissions&lt;/STRONG&gt; command you may receive the following error: &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color=#004080&gt;Set-EnrollmentPermissions : Error encountered when delegating container "OU=SCMDM Managed Devices (Instance1),DC=yonaloc,DC=nttest,DC=microsoft,DC=com" permission to Enrollment Server. &lt;BR&gt;At line:1 char:26 &lt;BR&gt;+ Set-EnrollmentPermissions&amp;nbsp; &amp;lt;&amp;lt;&amp;lt;&amp;lt; "SCMDM MAnaged Devices (Instance1)"&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Cause:&lt;/U&gt;&lt;/STRONG&gt; The Set-EnrollmentPermissions command verifies what permissions SCMDMEnrollmentServers has on the specified OU (i.e. the OU that is passed in the command).&amp;nbsp; There is a known issue in this verification process where it will return false if Full Permissions are enabled.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Resolution:&lt;/U&gt;&lt;/STRONG&gt; Do not enable full permission for SCMDMEnrollmentServers group on the device OU. To workaround this issue delete the SCMDMEnrollmentServers group from Security.&amp;nbsp; To do this follow these steps:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Run DSA.MSC. &lt;/LI&gt;
&lt;LI&gt;Find the OU where you were trying to set permissions. &lt;/LI&gt;
&lt;LI&gt;Right click on the OU and select Properties. &lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;On the Security tab, click on SCCMEnrollmentServers(&amp;lt;your instance name&amp;gt;) and remove it.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;The last step is to run the Set-EnrollmentPermissions command again.&amp;nbsp; This time it should succeed without error.&lt;/P&gt;
&lt;P&gt;========&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;J.C. Hornbeck | Manageability Knowledge Engineer&lt;/STRONG&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3169742" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mdm/archive/tags/Error/default.aspx">Error</category><category domain="http://blogs.technet.com/mdm/archive/tags/SP1/default.aspx">SP1</category><category domain="http://blogs.technet.com/mdm/archive/tags/CM/default.aspx">CM</category><category domain="http://blogs.technet.com/mdm/archive/tags/Enrollment/default.aspx">Enrollment</category></item><item><title>The same software package may be installed every time a device connects to a System Center Mobile Device Manager 2008 server</title><link>http://blogs.technet.com/mdm/archive/2008/12/10/the-same-software-package-may-be-installed-every-time-a-device-connects-to-a-system-center-mobile-device-manager-2008-server.aspx</link><pubDate>Wed, 10 Dec 2008 18:53:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3166290</guid><dc:creator>jchornbe</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mdm/comments/3166290.aspx</comments><wfw:commentRss>http://blogs.technet.com/mdm/commentrss.aspx?PostID=3166290</wfw:commentRss><description>&lt;p&gt;Here's an interesting MDM issue I ran across the other day.&amp;#160; If you're seeing the same package being installed again and again and again on your device then this may be what you're running up against:&lt;/p&gt;  &lt;p&gt;========&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Issue:&lt;/u&gt;&lt;/strong&gt; A software package may be installed every time a device connects to a System Center Mobile Device Manager 2008 server. The user of the device may also notice multiple entries for a software package under Managed Programs.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Cause:&lt;/u&gt;&lt;/strong&gt; If a managed Windows Mobile powered device is offered a software package through the MDM Software distribution console and the device installs the package, under certain conditions the status for the installation may not be received by the MDM server.&amp;#160; If this occurs, the software package is re-offered to the device and the device reinstalls it. The result is that the user may see the package installed multiple times and multiple entries for the package may appear in the Managed Programs history on the device.&lt;/p&gt;  &lt;p&gt;This issue can occur if the cab being installed reboots the device without prompting the user because the device goes offline after installing the software but before the next OMA session connection. The default OMA session connection interval (ConnectInterval value) is eight hours, so if the device then stays offline for longer than the software package re-offer period, MDM software distribution offers the package to the device again the next time that the device connects. The default setting for the re-offer period (ReofferPeriodInDays value) is seven days. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Resolution:&lt;/u&gt;&lt;/strong&gt; To resolve this problem please work with provider to repackage the cab so that it will prompt the user before rebooting the device.&lt;/p&gt;  &lt;p&gt;========&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;J.C. Hornbeck | Manageability Knowledge Engineer&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3166290" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mdm/archive/tags/Troubleshoot/default.aspx">Troubleshoot</category><category domain="http://blogs.technet.com/mdm/archive/tags/CM/default.aspx">CM</category></item><item><title>SCMDM: The management console is no longer available after installing the MDM Reporting Services v1.1 reporting snap-in</title><link>http://blogs.technet.com/mdm/archive/2008/12/09/scmdm-the-management-console-is-no-longer-available-after-installing-the-mdm-reporting-services-v1-1-reporting-snap-in.aspx</link><pubDate>Tue, 09 Dec 2008 17:00:19 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3165746</guid><dc:creator>jchornbe</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mdm/comments/3165746.aspx</comments><wfw:commentRss>http://blogs.technet.com/mdm/commentrss.aspx?PostID=3165746</wfw:commentRss><description>&lt;p&gt;Here's kind of a wacky issue we've seen a couple times so I thought I'd give you a heads up just in case you run into it.&amp;#160; If you're trying to run the MDM Management console on the same box as the MDM Reporting console and seeing things disappear then this may be your issue:&lt;/p&gt;  &lt;p&gt;========&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Issue:&lt;/u&gt;&lt;/strong&gt; The System Center Mobile Device Manager (MDM) management console is no longer available after installing the MDM Reporting Services v1.1 reporting snap-in.&amp;#160; This only occurs on the system on which the MDM Reporting MMC was installed.&amp;#160; Other MDM workstations that have installed the management console are unaffected. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Cause:&lt;/u&gt;&lt;/strong&gt; This is caused because the MDM v1.1 Reporting snap-in is registered into the MMC catalog with the same name as the main management console.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;Resolution:&lt;/u&gt;&lt;/strong&gt; Until the complete fix for this problem has been made available, the MDM Reporting Services snap-in and the MDM Management Console snap-in cannot both function if installed on the same machine.&amp;#160; To restore the MDM Management Console, run the SCMDM setup and re-install just the MDM Management Console.&lt;/p&gt;  &lt;p&gt;========&lt;/p&gt;  &lt;p&gt;Once an update for this becomes available an announcement should show up here on this blog or as part of a 'new KB' post.&amp;#160; Stay tuned...&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;J.C. Hornbeck | Manageability Knowledge Engineer&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3165746" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mdm/archive/tags/Troubleshoot/default.aspx">Troubleshoot</category><category domain="http://blogs.technet.com/mdm/archive/tags/CM/default.aspx">CM</category><category domain="http://blogs.technet.com/mdm/archive/tags/Console/default.aspx">Console</category><category domain="http://blogs.technet.com/mdm/archive/tags/Reporting/default.aspx">Reporting</category></item></channel></rss>