Machine Baseline Compliance
Machine Baseline Compliance
Distribution List
From Date Phone /Email
* Action Types: Approve, Review, Inform, File, Action Required, Attend Meeting, Other (please specify)
CONTENTS
1 Introduction ............................................................................................................................ 3
2 Report details ......................................................................................................................... 3
3 Remediation ........................................................................................................................... 5
3.1 SCCM Client Reinstallation ............................................................................................. 5
3.2 McAfee ........................................................................................................................... 6
Version 1.0
Machine Baseline Compliance Page 3 of 6
1 Introduction
This document describes machine baseline compliance report and remediation steps for
components with failed compliance state.
2 Report details
NHY domain:
Machine Baseline - SQL Server 2019 Reporting Services (hydro.com)
GLOBAL domain:
Machine Baseline - SQL Server Reporting Services (global.to)
Client Installed:
Shows the SCCM client installation status from SCCM server perspective.
Status:
Version 1.0
Machine Baseline Compliance Page 4 of 6
Heartbeat:
Shows the SCCM Client’s heartbeat status.
Status:
• OK: The heartbeat not older than 14 days compared to the last logon date.
• OLD: The heartbeat older than 14 days compared to the last logon date.
• N/A: The SCCM client hasn’t sent heartbeat.
Remediation: Reinstall SCCM client
HW inventory:
Shows the SCCM Client’s Hardware inventory status.
Status:
• OK: The HW inventory not older than 14 days compared to the last logon date.
• OLD: The HW inventory older than 14 days compared to the last logon date.
• N/A: The client hasn’t sent HW inventory
Remediation: Reinstall SCCM client
SW inventory:
Shows the SCCM Client’s Software inventory status.
Status:
• OK: The SW inventory not older than 14 days compared to the last logon date.
• OLD: The SW inventory older than 14 days compared to the last logon date.
• N/A: The SCCM client hasn’t sent SW inventory.
Remediation: Reinstall SCCM client
McAfee installed:
Shows the McAfee antivirus installation status.
Status:
• Compliant: McAfee and all required modules are installed on the machine.
• Non-Compliant: McAfee not installed, or some required modules are missing.
Remediation: Install McAfee
Zscaler installed:
Shows the Zscaler antivirus installation status.
Status:
• Compliant: Zscaler installed on the machine.
• Non-Compliant: Zscaler not installed on the machine.
Remediation: Install Zscaler
3 Remediation
Logfiles:
• Script Logfiles:
C:\Windows\Hydro\Logs\CCMClientRemediation
Troubleshooting:
• If Corporate connection available run “gpupdate /force”. It should copy the latest binaries
and create the scheduled tasks
Version 1.0
Machine Baseline Compliance Page 6 of 6
NHY:
\\nhy.hydro.com\SYSVOL\nhy.hydro.com\Policies\{E3BF8148-3742-4264-ADFE-
A46C63FCA63F}\Machine\Script\CCMClientRemediation
Global:
\\global.to\sysvol\global.to\scripts\Scripts\CCMClientRemediation
to a separate temporally folder and run the script with elevated PowerShell Prompt:
After successful reinstallation it takes approx. 24 hours to get all SCCM policies and
advertisements.
3.2 McAfee
Automatic remediation:
• The SCCM regularly checks McAfee agent compliance and initiate automatic reinstallation
if any components are missing.
This will force computer restart!
Manual Reinstall:
• Open SCCM device and application Manager tool
• Select “Assign Device Software” TAB
• Add machine to “McAfee Reinstall” Software.
• This initiate automatic reinstallation of McAfee agent