通过SCCM配置项/基线禁用NetBIOS遇合规评估错误
Let me walk through targeted fixes and checks based on your scenario—since your discovery/recovery scripts work locally but SCCM throws errors when the TcpIPNetBiosOptions registry value isn't set to 2, here are the key areas to investigate:
1. Fix Data Type Mismatch in Discovery Script
SCCM is strict about data type consistency, and this is a common culprit:
- The
TcpIPNetBiosOptionsregistry value is stored as a DWORD (integer), but your script is comparing it to a string"2". This type mismatch can cause SCCM to interpret the evaluation as an error instead of non-compliance. - Update your comparison logic to use integer values:
# Replace string comparison with integer check if ($adapter.TcpIPNetBiosOptions -ne 2) { return $false # Mark as non-compliant } else { return $true # Mark as compliant }
2. Test Script Under SYSTEM Account Context
Local scripts run under your user permissions, but SCCM compliance policies execute under the SYSTEM account, which has different access rights:
- Use
psexec -s powershell.exeto launch a PowerShell session as SYSTEM, then run your discovery script. If it fails here, you’ve found the root cause. - Ensure the SYSTEM account has read access to the registry path:
HKLM:\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces\*
3. Validate SCCM Compliance Rule Configuration
Double-check your policy’s rule setup to avoid misalignment:
- Navigate to your compliance policy’s Rules tab. Confirm you’ve configured the rule to check for the script’s return value as "Equals
True" for compliant status. - Avoid custom error codes unless your script explicitly returns them—stick to simple
$true/$falseoutputs for discovery scripts, as SCCM handles these most reliably.
4. Dig Into Client-Side Logs for Exact Error Details
SCCM client logs will show you exactly why the evaluation failed:
- Check the ComplianceHandler.log on problematic clients. Look for entries like
Script execution failedorNon-compliant result with error codeto get specific context. - The PolicyAgent.log can also help verify if the policy was downloaded and applied correctly.
5. Add Error Handling for Missing Registry Keys
If your script iterates over multiple network adapters, some adapters might not have the TcpIPNetBiosOptions value, causing script failures:
- Update your script to skip adapters where the registry key doesn’t exist:
$adapterPaths = Get-ChildItem "HKLM:\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces" foreach ($path in $adapterPaths) { $netBiosSetting = Get-ItemProperty -Path $path.PSPath -Name TcpIPNetBiosOptions -ErrorAction SilentlyContinue # Only check if the value exists and is not 2 if ($netBiosSetting -and $netBiosSetting.TcpIPNetBiosOptions -ne 2) { return $false } } return $true
Most of the time, the issue boils down to data type mismatches or permission gaps when running under the SYSTEM account. Give these steps a shot, and you should resolve the evaluation error.
内容的提问来源于stack exchange,提问作者user001

