Keeping a gold image up-to-date for a linked clone environment.

This is one of those questions that floats in a grey area. MS will probably say this is a VMWare issue, and VMWare will say it's an MS issue.

For several months now I've been fighting with VDI machines showing up in my SCCM environment. There are 4 gold images that get used for the linked clones that VMWare View uses to create the VDI sessions. Without the SCCM client I would have to manually patch and update all the software on each of those gold images. The ideal situation would be to have the SCCM client on just the gold image and not on the linked clones, but I'm told there isn't an easy way to remove the SCCM client then re-install it next month when the time comes to recompose the pools.

I have been reading up on this for a couple of days now. This link here while for 2007 showed some promise all though not what i'm trying to do. https://social.technet.microsoft.com/Forums/systemcenter/en-US/0299ef48-a4d2-4536-b42d-2083b110603f/sccm-2007-in-combination-with-vmware-view-40?forum=configmgrgeneral

Whats been tried so far to keep the VDI sessions from bleeding back into the environment? A gpo was created to stop the CCM service. Disabled the task schedule health task for configmgr. So far these have proven to be half measures.

Some things i'm debating.....Since we run PKI HTTPS only I'm thinking about trying to delete both the client and SMS certificates from gold image and modify the cert. template permissions. Also going to disable the WUAUSERV service. I need to try something. I've got about 2500 devices showing up in the SMS DB weekly sometimes as quick as a couple of days. 

Any additional ideas would be greatly appreciated. Please try and refrain from saying contact VMWare this isn't an SCCM MS problem. For some odd reason I feel like thats coming.:-)

Thanks in advance...gotta run, missing Game of Thrones!

-KR

April 19th, 2015 9:29pm

Hi,

How about using WSUS to update all the softwares on each of the gold images instead of SCCM? Here is a blog that using WSUS and PowerShell script to complete the task.

Patch Tuesday VDI Pains? Weve got a script for that(Part 1 and 2)

http://seanmassey.net/2013/09/30/patch-tuesday-vdi-pains-weve-got-a-script-for-that-part-1/

Note: Microsoft provides third-party contact information to help you find technical support. This contact information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.

Best Regards,

Joyce

Free Windows Admin Tool Kit Click here and download it now
April 21st, 2015 2:03am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics