You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过SCCM配置项/基线禁用NetBIOS遇合规评估错误

Troubleshooting SCCM Compliance Policy Error for NetBIOS Disablement

Let me walk through targeted fixes and checks based on your scenario—since your discovery/recovery scripts work locally but SCCM throws errors when the TcpIPNetBiosOptions registry value isn't set to 2, here are the key areas to investigate:

1. Fix Data Type Mismatch in Discovery Script

SCCM is strict about data type consistency, and this is a common culprit:

  • The TcpIPNetBiosOptions registry value is stored as a DWORD (integer), but your script is comparing it to a string "2". This type mismatch can cause SCCM to interpret the evaluation as an error instead of non-compliance.
  • Update your comparison logic to use integer values:
    # Replace string comparison with integer check
    if ($adapter.TcpIPNetBiosOptions -ne 2) {
        return $false # Mark as non-compliant
    } else {
        return $true # Mark as compliant
    }
    

2. Test Script Under SYSTEM Account Context

Local scripts run under your user permissions, but SCCM compliance policies execute under the SYSTEM account, which has different access rights:

  • Use psexec -s powershell.exe to launch a PowerShell session as SYSTEM, then run your discovery script. If it fails here, you’ve found the root cause.
  • Ensure the SYSTEM account has read access to the registry path: HKLM:\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\*

3. Validate SCCM Compliance Rule Configuration

Double-check your policy’s rule setup to avoid misalignment:

  • Navigate to your compliance policy’s Rules tab. Confirm you’ve configured the rule to check for the script’s return value as "Equals True" for compliant status.
  • Avoid custom error codes unless your script explicitly returns them—stick to simple $true/$false outputs for discovery scripts, as SCCM handles these most reliably.

4. Dig Into Client-Side Logs for Exact Error Details

SCCM client logs will show you exactly why the evaluation failed:

  • Check the ComplianceHandler.log on problematic clients. Look for entries like Script execution failed or Non-compliant result with error code to get specific context.
  • The PolicyAgent.log can also help verify if the policy was downloaded and applied correctly.

5. Add Error Handling for Missing Registry Keys

If your script iterates over multiple network adapters, some adapters might not have the TcpIPNetBiosOptions value, causing script failures:

  • Update your script to skip adapters where the registry key doesn’t exist:
    $adapterPaths = Get-ChildItem "HKLM:\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces"
    foreach ($path in $adapterPaths) {
        $netBiosSetting = Get-ItemProperty -Path $path.PSPath -Name TcpIPNetBiosOptions -ErrorAction SilentlyContinue
        # Only check if the value exists and is not 2
        if ($netBiosSetting -and $netBiosSetting.TcpIPNetBiosOptions -ne 2) {
            return $false
        }
    }
    return $true
    

Most of the time, the issue boils down to data type mismatches or permission gaps when running under the SYSTEM account. Give these steps a shot, and you should resolve the evaluation error.

内容的提问来源于stack exchange,提问作者user001

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 10:21:14