cancel
Showing results for 
Search instead for 
Did you mean: 
Lenovo Staff
Views: 18,468

Lenovo Patch for SCCM User Guide, Upgrade Guide, and Release Notes

 

 

Systems Requirements

 

A.  Configuration Manager version:

  • 2012 R2 SP1 through Current Branch

B. Operating System where the Configuration Manager console is installed must be a 64-bit version of one of the following (excludes Server Core and Nano):

  • Windows Server 2019
  • Windows Server 2016

  • Windows Server 2012 R2

  • Windows Server 2012

  • Windows Server 2008 R2 SP1

  • Windows 10 Pro or Enterprise Edition

  • Windows 8.1

  • Windows 7 SP1

C.  Microsoft Visual C++ 2015-2019 Redistributable (x86 and x64)

  • If either of these requirements are missing, they will be installed during the installation of Lenovo Patch.

D.  .NET Framework 4.8 or later

  • If this requirement is missing, .NET Framework 4.8 will be installed during the installation of Lenovo Patch.  This install will require a reboot.

 

E.  Windows Server Update Services (WSUS) client:

  • If Lenovo Patch for SCCM is installed on the Primary Configuration Manager server and the server operating system is either Windows Server 2016, Windows Server 2012 R2, or Windows Server 2012, then the WSUS API and the PowerShell cmdlets features must be installed and enabled.

  • If Lenovo Patch for SCCM is installed on a remote Windows 10, Windows 8.1, or Windows 7 SP1 computer requires the associated version of Remote Server Administration Tools (RSAT) to be installed and enabled. 

  • If the primary WSUS server is running WSUS 3.0 SP2, then the WSUS 3.0 SP2 Administration Console must be installed on the same machine as Lenovo Patch. Patches KB2720211 and KB2734608 must be applied to both the WSUS server and the Configuration Manager Console machines.

F.  Shared Settings

  • Each user taking advantage of the Shared Settings feature requires access to a SQL Server database and must have read/write permissions to the database.  Any version of Microsoft SQL Server supported by the currently installed Microsoft SCCM version is valid.

G.  Scheduled Tasks

  • If there is intention to automatically publish updates using a recurring scheduled task, then the Microsoft Task Scheduler service must be.
  • The user executing the scheduled task must be granted Log on as a batch job rights.

H.  Alerts

  • If there is intention to receive alert notifications via email, then SCCM must be configured to allow email notifications.For more information, refer to the Managing Alerts section of the Lenovo Patch for SCCM 2.4 User Guide at the beginning of this article.

I.  License

  • Lenovo Patch for SCCM activation code must be entered when purchased or be activated via the trial activation option.

J.  User Rights

  • Be a member of the WSUS Administrators group on the WSUS server.

  • The user account must be assigned to the Full Administrator Security Role in the Configuration Manager application.
  • Have Log on as a batch job rights

  • Be assigned to the All instances of the objects that are related to the assigned security roles security scope.

  • In addition, if the WSUS Server is remote, the user must be a member of the local administrators group on the WSUS Server.

K.  Client Machines

  • Each of your client machines must meet the following requirements to deploy non-Microsoft updates distributed by a WSUS server:
    • Must contain a copy of the code signing certificate in the appropriate certificate stores
    • Must have enabled the Allow signed updates from an intranet Microsoft update service location policy setting.

    • Must have the LUC Agent installed on Lenovo devices.  For more information, please visit: LUC Agent - Deploy Me First.

L.  Firewall

  • The firewall, proxy, and web filter will require a several URLs to be added to the respective exception lists. The URLs are used by Lenovo Patch for SCCM to download updates from third-party vendors.
  • For the complete list of URLs to add, please visit: Lenovo Patch Web URLs.

M.  Federal Information Processing Standard (FIPS) environments

  • When operating in a FIPS environment, the console must be configured as a FIPS-compliant machine before Lenovo Patch for SCCM is installed. If FIPS is enabled after the installation, Lenovo Patch for SCCM must be reinstalled.

Was this information helpful?