通过SCCM部署PowerShell脚本安装软件失败求助
排查SCCM部署Evolven Agent脚本失败问题
问题描述
尝试通过SCCM部署封装了批处理脚本的PowerShell脚本(EvolvenInstaller.ps1),但部署始终无法正确完成安装:
- 手动运行脚本时一切正常,所有组件均可成功安装;
- 通过SCCM部署时,系统显示部署成功,但实际软件并未安装。
已确认的配置信息:
- 共享目录中存在全部所需脚本;
- SCCM部署配置:
- 安装参数:
powershell.exe -ExecutionPolicy Bypass -NoProfile -WindowStyle Hidden -File EvolvenInstaller.ps1 - 启动路径:
%~dp0
- 安装参数:
执行的PowerShell脚本内容:
<# .Evolven Agent Installer - Working Version .Handles UNC paths properly #> $logDir = "C:\EvolvenLogs" $installLog = "$logDir\EvolvenInstall_$(Get-Date -Format 'yyyyMMdd-HHmmss').log" $installDir = "C:\Program Files\Evolven Enlight\Evolven Agent" $timeoutMinutes = 30 # Ensure log directory exists New-Item -ItemType Directory -Path $logDir -Force | Out-Null function Write-Log { param([string]$message) $logEntry = "$(Get-Date -Format 'yyyy-MM-dd HH:mm:ss') - $message" Add-Content -Path $installLog -Value $logEntry -Force Write-Host $logEntry } try { Write-Log "=== STARTING EVOLVEN AGENT INSTALLATION ===" Write-Log "Current Location: $(Get-Location)" Write-Log "Current User: $env:USERNAME" # Check if batch file exists $batchFile = "silent.install.bat" if (-not (Test-Path $batchFile)) { throw "Batch file not found: $batchFile" } Write-Log "Found batch file: $batchFile" # Get full path to batch file $fullBatchPath = (Get-Item $batchFile).FullName Write-Log "Full batch path: $fullBatchPath" Write-Log "Starting installation process..." $startTime = Get-Date Write-Log "Executing: cmd.exe /c `"$fullBatchPath`"" # Simple approach - just run it and wait $process = Start-Process -FilePath "cmd.exe" -ArgumentList "/c", "`"$fullBatchPath`"" -Wait -PassThru -NoNewWindow $endTime = Get-Date $runtime = $endTime - $startTime Write-Log "Process completed in $($runtime.TotalSeconds) seconds" Write-Log "Exit code: $($process.ExitCode)" if ($process.ExitCode -ne 0) { throw "Installation failed with exit code $($process.ExitCode)" } # Verify installation Write-Log "Verifying installation..." Start-Sleep -Seconds 5 # Give it a moment if (Test-Path $installDir) { Write-Log "Installation directory found: $installDir" } else { Write-Log "WARNING: Installation directory not found at $installDir" } Write-Log "=== INSTALLATION COMPLETED SUCCESSFULLY ===" Exit 0 } catch { Write-Log "=== INSTALLATION FAILED ===" Write-Log "ERROR: $($_.Exception.Message)" Write-Log "Details: $($_.ScriptStackTrace)" Exit 1 }
排查思路
优先检查日志文件
- 查看脚本生成的
C:\EvolvenLogs\EvolvenInstall_*.log,重点确认:- 当前执行路径是否为预期的SCCM缓存目录或共享目录
- 当前执行用户是否为
SYSTEM(SCCM默认执行账户) - 批处理文件是否被成功找到,以及执行后的退出码
- 查看SCCM客户端日志:
%WinDir%\CCM\Logs\AppEnforce.log:确认部署执行的详细过程、文件复制状态、权限问题%WinDir%\CCM\Logs\Script.log:查看PowerShell脚本的完整执行输出
- 查看脚本生成的
验证SYSTEM账户执行场景
- 使用
psexec.exe -s -i powershell.exe打开SYSTEM权限的PowerShell窗口 - 切换到SCCM客户端缓存目录(通常为
C:\Windows\ccmcache\<随机字符文件夹>) - 手动执行
.\EvolvenInstaller.ps1,观察是否能正常完成安装,以此排查权限或环境变量差异问题
- 使用
确认SCCM文件缓存与启动路径
- 检查
%WinDir%\CCM\Logs\ContentTransferManager.log,确认所有脚本文件是否成功下载到客户端缓存 - 手动进入缓存目录,确认
EvolvenInstaller.ps1和silent.install.bat均存在 - 修改脚本,在
Write-Log中添加当前路径的父目录信息,验证%~dp0在SCCM上下文是否正确解析
- 检查
增强脚本的错误捕获能力
- 修改
Start-Process命令,捕获批处理的标准输出和错误输出:$process = Start-Process -FilePath "cmd.exe" -ArgumentList "/c", "`"$fullBatchPath`"" -Wait -PassThru -NoNewWindow ` -RedirectStandardOutput "$logDir\batch_stdout.log" ` -RedirectStandardError "$logDir\batch_stderr.log" - 在日志中添加对批处理输出文件的读取和记录,便于定位批处理内部的执行错误
- 优化安装验证逻辑,不仅检查安装目录是否存在,还要验证关键文件(如
EvolvenAgent.exe)是否存在且大小正常
- 修改
检查SCCM部署配置选项
- 确认部署是否设置为以系统账户运行,若脚本需要交互式权限,需调整为“以用户身份运行”并勾选允许交互
- 检查部署超时设置,避免因安装过程超过默认超时被强制终止
- 测试时暂时去掉
-WindowStyle Hidden参数,观察是否有错误弹窗被隐藏导致安装失败
内容的提问来源于stack exchange,提问作者Kevin
相关产品推荐
相关产品推荐

