One of the new features of ConfigMgr 2012 is the ability to auto remediate a computer’s baseline that does not match a desired configuration. I have listed the steps to configure auto remediation and apply the baseline to a collection. This functionality is very useful to maintain "Gold Build" configurations, (local security policies, registry keys and installed programs) and to correct any drifting of your production computer baselines. After the Compliance task runs there are several ConfigMgr 2012 reports that can be run to demonstrate the changes that were made to the baseline of the target computer.
- Launch ConfigMgr 2012 > Click on Assets and Compliance in the WonderBar
- Right Click Configuration Items > Create Configuration Item
- Enter the name for this Configuration Item. In this case we want to check on the Windows Firewall setting registry key > Click Next
- Select the version of Windows you want this Configuration Item to be applied to > Click Next
- On the Specify settings for this operating system page > Click New
- Enter the name for this setting
- Setting type Registry
- Data type integer
- Hive HKEY_LOCAL_MACHINE > Click Browse
- Browse the Windows Registry to the key that must exist for this Compliance Setting
- Highlight the Registry key in the Name field
- Check the "Select the rule that defies compliance for the selected registry value" checkbox
- Select "The selected registry value must exist on client devices" radio button
- Check the "This registry value must satisfy the following rule if present" checkbox > Click OK > Click OK
- Click Next
- Highlight the setting condition > Click Edit
- Check Remediate noncompliant rules when supported
- Check Report noncompliance if this setting is not found
- Click OK > Click Next
- Review the Summary Page > Click Next
- Click Close
- Add the Configuration Item to a Configuration Baseline > Right Click Configuration Baselines > Select Create Configuration Baseline
- Type the name for the Configuration Baseline > Click Add Configuration Item
- Select the Configuration Item > Click Add >Click OK
- Click OK
- Right Click the Configuration Baseline > Deploy
- Add the Configuration Baseline
- Select the Remediate noncompliant rules when supported
- Select Generate Alert
- Click Browse to Select the Collection you want this Baseline applied to
- Configure the schedule to suit your environments needs
- Click OK
- Click OK
"The postings on this site are my own and don’t necessarily represent Microsoft’s or my employer’s positions, strategies or opinions"