SCCM客户端缺失补丁关联部署查询及PowerShell模块优化需求
解决方案:SCCM客户端缺失补丁关联部署查询与PowerShell模块优化
Alright, let's break down how to solve both of your SCCM-related tasks. I'll start with listing deployments tied to missing patches, then help you optimize that PowerShell module to organize updates neatly by deployment with deadlines included.
1. 列出与缺失补丁关联的SCCM部署
To pull deployments linked to missing patches on an SCCM client, we'll use CIM cmdlets (the modern replacement for WMI) to query two key WMI classes:
CCM_UpdateStatus: Tracks the status of all software updates on the clientCCM_UpdateAssignment: Stores details about SCCM update deployments
Here's the code to tie them together:
# Grab all missing updates (Status=2 = Missing; adjust if your environment uses a different code) $missingUpdates = Get-CimInstance -Namespace root\ccm\SoftwareUpdates\UpdatesStore -ClassName CCM_UpdateStatus | Where-Object { $_.Status -eq 2 } # Fetch all active update deployments on the client $deployments = Get-CimInstance -Namespace root\ccm\Policy\Machine\ActualConfig -ClassName CCM_UpdateAssignment # Link missing updates to their parent deployments, then deduplicate deployments $linkedDeployments = $missingUpdates | ForEach-Object { $update = $_ $deployments | Where-Object { $_.AssignmentID -eq $update.AssignmentID } | Select-Object @{Name='DeploymentName';Expression={$_.AssignmentName}}, @{Name='AssignmentID';Expression={$_.AssignmentID}}, @{Name='Deadline';Expression={[Management.ManagementDateTimeConverter]::ToDateTime($_.Deadline)}} } | Select-Object -Unique | Sort-Object Deadline # Output the results $linkedDeployments
Quick notes:
- The
Statusvalue inCCM_UpdateStatusvaries by state: 1 = Installed, 2 = Missing, 3 = Pending Installation, 4 = Pending Reboot. Double-check your client's status codes if needed. - We use
Select-Object -Uniqueto avoid repeating the same deployment multiple times (once per missing patch).
2. 优化PowerShell模块:按部署整理缺失补丁
Your existing code grabs missing updates, but we can extend it to group updates by deployment, show deadlines, and make the output human-readable. Here's a polished function you can drop into your module:
function Get-SCCMMissingUpdatesByDeployment { [CmdletBinding()] param( [string]$ComputerName = $env:ComputerName ) # Get missing updates from the client $missingUpdates = Get-CimInstance -ComputerName $ComputerName -Namespace root\ccm\SoftwareUpdates\UpdatesStore -ClassName CCM_UpdateStatus | Where-Object { $_.Status -eq 2 } if (-not $missingUpdates) { Write-Host "No missing updates found on $ComputerName." -ForegroundColor Gray return } # Fetch all update deployments $updateAssignments = Get-CimInstance -ComputerName $ComputerName -Namespace root\ccm\Policy\Machine\ActualConfig -ClassName CCM_UpdateAssignment # Associate each missing update with its deployment, then group by deployment name $groupedResults = $missingUpdates | ForEach-Object { $update = $_ $matchingDeployment = $updateAssignments | Where-Object { $_.AssignmentID -eq $update.AssignmentID } if ($matchingDeployment) { [PSCustomObject]@{ DeploymentName = $matchingDeployment.AssignmentName Deadline = [Management.ManagementDateTimeConverter]::ToDateTime($matchingDeployment.Deadline) UpdateTitle = $update.Title UpdateID = $update.UpdateID } } } | Group-Object -Property DeploymentName # Print formatted results foreach ($deploymentGroup in $groupedResults) { Write-Host "`n=== Deployment: *$($deploymentGroup.Name)* ===" -ForegroundColor Cyan Write-Host "Installation Deadline: $($deploymentGroup.Group[0].Deadline)" -ForegroundColor Yellow Write-Host "Missing Updates:" -ForegroundColor Green $deploymentGroup.Group | ForEach-Object { Write-Host "- $($_.UpdateTitle) (Update ID: $($_.UpdateID))" } } # Optional: Export to CSV for reporting # $groupedResults | Select-Object Name, @{Name='Deadline';Expression={$_.Group[0].Deadline}}, @{Name='MissingUpdates';Expression={$_.Group.UpdateTitle -join ';'}} | Export-Csv -Path "SCCMMissingUpdates.csv" -NoTypeInformation } # Example usage: Get-SCCMMissingUpdatesByDeployment
Key improvements:
- Grouped output: Updates are organized under their parent deployment, making it easy to see which deployments have unapplied patches.
- Deadline visibility: Converts SCCM's WMI datetime format to a readable date/time string.
- Remote support: The
ComputerNameparameter lets you run this against remote SCCM clients (as long as you have WMI/CIM access). - No console access required: This only needs local admin (or appropriate WMI permissions) on the client, no SCCM console rights.
内容的提问来源于stack exchange,提问作者Keith
相关产品推荐
相关产品推荐

