White Papers
20 Update 1803 for Cloud Platform System (CPS) Standard
Also, if you do not intend to apply the 1803 Microsoft package immediately, follow the steps in the "Post-
update clean up" section of the Dell Hybrid Cloud System for Microsoft CPS Standard Administrators Guide
after you have completed the update.
4.2.1 Run an optional compliance scan
If you want to run a compliance scan, pass the following flag:
\\SU1_InfrastructureShare1<CPSPU FolderName>\Framework\PatchingUpgrade\Invoke-
PURun.ps1 -PUCredential $cred -ComplianceScanOnly
The compliance scan output is written to the following location, the place where the update package was
extracted. For example, the following shows output written to:
"PURoot"\MissingUpdates.json
Post-update manual steps
1. KB#3000483 is a Windows Group Policy related security update (CVE-2015-0008). It requires both the
binary files (delivered in P&U 1611 and 1703), and a Group Policy update. See the KB article for details
on the Group Policy changes, including a section titled “Minimum recommended configuration for domain-
joined computers”. (Review the KB article, and decide how to implement for your organization and CPS
domain.)
2. KB#4038792 (Released in P&U 1803) includes a fix for security vulnerability CVE-2017-8529. Two
additional registry changes needs to be implemented through an Active Directory Group Policy Object
(AD GPO). See the CVE article for the 2 registry keys that need to be implemented for 64-bit systems.
3. KB#3170005 (Released in P&U 1803) will prevent the installation of some printers (non-package aware
Version 3 printer drivers). If these older pre-Windows Vista printer drivers are being used with CPS, follow
the steps in the KB article for creation of Active Directory Group Policy Object (AD GPO) to allow these
older drivers. This change is not required if these older printer drivers are not in use.
Manually update the SMA Management Packs (MPs) for SCOM
Apply the updated SMA MPs into the SCOM Operations Console.
1. On the Console VM, open the SCOM Operations Console to import the MPs:
a. Navigate to: Administration | Management Packs.
b. In the right pane of the SCOM Operations Console, click on “Import Management Packs…”
c. In the Import Management Packs window, click on Add | Add from Disk…
d. Select “No” on the question of whether to search online for dependencies.
e. In the Import selection window, browse to the P&U share on the Console VM. Path similar to
this (local to the Console VM):
C:\PU_Share\1706\PU\Payload\MgmtAssets\ManagementPacks.
f. Select the three files beginning with
“Microsoft.SystemCenter.ServiceManagementAutomation” in the 1803 P&U package.
g. Click on Open to select these three files into the import screen.
h. Click on “Install” to install these updated MP files for SMA.