10.7 Config Profile Not Distributing

btaitt
Contributor

Hey all,

I have an 802.1x profile going out to our 384 Lion managed clients. Unfortunately when making a change (the only way, it seems, to see how many computers a profile has gone out to) it says that there are only 225 clients that have this profile. As we transition to our new wireless security, this is a big problem that 160 clients are not getting the 802.1x profile.

Why would a configuration profile not be going out to all managed clients? Do I have to delete this one and try a new one?

1 ACCEPTED SOLUTION

gregp
Contributor

We're also seeing that with our Mtn Lion clients.

Have seen other inconsistencies with other config profiles and as a result, only use config profiles that are cosmetic and don't adversely impact our users (e.g. the legalese text at the login screen).

We're now using a script to configure the WiFi and to shove in the 802.1x profile. While not ideal, far better than created another OS disk image that would need to be maintained. Plus, its reliable.

View solution in original post

3 REPLIES 3

gregp
Contributor

We're also seeing that with our Mtn Lion clients.

Have seen other inconsistencies with other config profiles and as a result, only use config profiles that are cosmetic and don't adversely impact our users (e.g. the legalese text at the login screen).

We're now using a script to configure the WiFi and to shove in the 802.1x profile. While not ideal, far better than created another OS disk image that would need to be maintained. Plus, its reliable.

btaitt
Contributor

Gregp,

That very well may be the way we need to go. Would you mind sharing the script you use so we could have a place to start from?

jafuller
Contributor

Profiles are MDM (.mobileconfig) based. Therefore they require that the server is available for communication with the client and that APNs isn't down/slow. If these computers are offline for any amount of time, that configuration may be in "pending" status.

Go to the computer record of one of your clients that hasn't received the profile and click into the Details. Then go to Management History. Click the circular arrow in the top right corner to refresh any pending commands. See if it goes out.

There aren't any reporting or grouping capabilities that I can find to pull all computers with Pending commands and refresh them. I'd like that though.