The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Microsoft Configuration Manager current branch version 2309 became globally available on November 1, 2023. It added improvements for Windows 11 servicing, PXE, cloud management, scripting and site maintenance, alongside a mandatory SQL connectivity prerequisite. It is now a historical release, not a current deployment recommendation; this guide is useful for administrators maintaining or evaluating a 2309 environment.
Microsoft’s release documentation is the authority for behavior and upgrade eligibility: it lists version 2207 or later as the source-version requirement. Some capabilities also need updated clients, not just an updated site and console.
SCCM 2309 at a glance
“SCCM” remains a common name for Microsoft Configuration Manager. Version 2309 is an in-console current-branch update that updates site components and the console, with client updates handled as a related but distinct step. Microsoft’s 2309 release notes describe the features and prerequisites.
| Area | Change | Operational value | Key qualification |
|---|---|---|---|
| Infrastructure | ODBC Driver for SQL Server 18.1.0 or later | Required dependency for site and site-system roles | Administrators install and maintain it; ConfigMgr does not update it automatically. |
| Automation | Scheduled script execution | Run approved scripts at a specified time | Scheduled time is UTC. |
| Site maintenance | Aged task-execution status cleanup | Remove old records from the task-execution status table | Default retention is records older than 30 days; check retention needs. |
| Software updates | Native Windows restart experience | Use a Windows-native restart experience for update restarts | Microsoft specifies Windows 11 version 22H2 or later. |
| OS deployment | Preferred management point for PXE | Route PXE clients toward an appropriate management point | Depends on accurate boundaries and management-point configuration. |
| BitLocker | Recovery-key escrow during provisioning | Make recovery information available earlier in deployment | Successful escrow depends on task-sequence execution, permissions and encryption state. |
| Windows 11 | Edition-upgrade policy and readiness dashboard | Support edition changes and upgrade planning | Neither removes licensing requirements nor replaces compatibility testing. |
| Cloud management | Improved CMG application workflow | Simplify tenant and application selection | Application registration, permissions and CMG operation still need configuration. |
| Integrations | Azure Logic App notification run details | Expose supported notification run details in the console | Not a replacement for Azure workflow monitoring. |
The article that originally popularized the feature list is available at HTMD Blog. Its version and date claims need historical context: Microsoft says global availability was November 1, 2023, following earlier opt-in availability.
#1 Best Overall
- Brilliant Display – Stunning 13.8" PixelSense touchscreen[1], with brilliant LCD display[2], unleashes luminous whites, deeper blacks and colors so richly saturated bringing vivid life into every frame – perfect for work, school, streaming and creative tasks.
- Power that lasts all day – With 20 hours of battery life[3], the new Surface Laptop powers through your entire day, so you can create, work and stream from morning to night without reaching for a charger.
- Work at the speed of your ideas – Built with the latest Qualcomm Snapdragon X2 Elite (12 Core) processors, Surface Laptop delivers fast, AI‑accelerated performance—making it the most powerful Surface laptop for everything from multitasking to demanding workloads.
- The ports you need – Charge on-the-go, transfer data fast, or create the ultimate desktop set up with two USB-C / USB4[4] ports.
- Built-in AI Companion – Work smarter, create freely, and communicate with confidence—Copilot[5] on Windows 11 is always there to help.
Who should care about version 2309?
Its features are most relevant when documenting, troubleshooting or upgrading an existing Configuration Manager estate. In its release context, the strongest operational reasons to consider it included Windows 11 update handling, distributed PXE routing, CMG setup changes and the fixes bundled with the release.
- High operational impact: the ODBC prerequisite, site-and-client update sequencing, PXE preferred-MP behavior, Windows 11 readiness and restart experience, and CMG application workflow.
- Moderate impact: scheduled scripts, ProvisionTS BitLocker escrow, Windows 11 edition policies and expanded maintenance-window offsets.
- Administrative maintenance: Logic App run details, aged status cleanup and fixes to console, client and compliance behavior.
Do not use 2309 as the default target for a new 2026 deployment. Check Microsoft’s currently supported releases and servicing guidance before choosing a target; this article does not establish the current support status of 2309.
Prerequisites and upgrade readiness
Microsoft documents version 2207 or later as eligible for the 2309 update. An HTMD article says 2203 or later, but for upgrade planning use Microsoft’s documented 2207 threshold and confirm the console offers the update for your site.
- Install Microsoft ODBC Driver for SQL Server version 18.1.0 or later on site servers and relevant remote site-system roles before upgrading. Inventory every server and verify architecture and installation requirements.
- Do not assume Configuration Manager will install or keep the ODBC driver current. Do not remove SQL Server Native Client 11 unless applicable Microsoft guidance explicitly permits it.
- Confirm the service connection point is working where required, and check update synchronization and download status.
- Run the prerequisite checker, resolve blocking errors and investigate warnings. Review Microsoft’s Configuration Manager update guidance and the post-update checklist.
- Plan a site backup, maintenance window, client pilot and recovery approach. Identify the services and workflows that must be tested after installation.
Some features may appear in the console after the site update but are not fully functional until clients are upgraded. Treat site, console and client versions as separate validation points.
Infrastructure, scripting and maintenance changes
ODBC Driver 18.1.0 or later is a prerequisite
Version 2309 requires Microsoft ODBC Driver for SQL Server 18.1.0 or later when creating or updating a site and for remote site-system roles. Install it before upgrading, include it in server build and patch procedures, and rerun prerequisite checks after remediation.
Schedule script execution in UTC
The Run Script Wizard adds scheduling, and the PowerShell cmdlet Invoke-CMScript gains the ScheduleTime parameter. The scheduled time is UTC, not the operator’s local time. Convert carefully for the target region, account for daylight-saving changes and document the local equivalent for operations staff.
$ScriptObj = Get-CMScript -ScriptName "test"
Invoke-CMScript `
-InputObject $ScriptObj `
-CollectionId "SMSDM003" `
-ScheduleTime "08/02/2023 07:35:00"
Use a test collection and verify approval state, target membership and returned results before scheduling production scripts. The example’s date and time illustrate syntax; interpret the supplied schedule as UTC.
Rank #2
- With 16 GB of memory, runs as many programs as you want without losing the execution
- The 13.5" 2256 x 1504 screen provides a great movie watching experience
- 512 GB SSD is enough to store your essential documents and files, favorite songs, movies and pictures
- 8 Hours battery run time helps you stay unwired and work longer non-stop
Review Azure Logic App notification run details
For supported external-service notifications generated through Azure Logic Apps, administrators can see run details in Configuration Manager. This can help connect a ConfigMgr event to a Logic App action or notification, but Azure authentication, permissions, connectors and workflow health remain separate. Continue to use Azure monitoring for the workflow itself.
Configure aged task-execution status cleanup
The new site-maintenance task, Delete Aged Task Execution Status Messages, is available on primary servers. Its default schedule is Saturday, and its default retention removes records older than 30 days from [dbo].TaskExecutionStatus. Review audit, troubleshooting and reporting requirements before changing the schedule or retention.
Set-CMSiteMaintenanceTask `
-Sitecode "XXX" `
-MaintenanceTaskName "Delete Aged Task Execution Status Messages" `
-DaysOfWeek Friday
Software-update and maintenance-window improvements
Native restart experience for supported Windows 11 clients
On Windows 11 version 22H2 or later, client device settings can select Windows as the restart experience in the computer-restart configuration. Restart notifications can include organizational branding. This changes how users experience a restart; it does not replace deployment deadlines, maintenance windows or restart planning.
Test the experience with shared devices, kiosks, VDI, remote users and devices with strict uptime requirements. Also check behavior where update deployments or restart policies overlap. Microsoft’s 2309 documentation does not extend this specific condition to Windows 10.
Expanded maintenance-window offsets
The relevant PowerShell functionality expands its offset range from 0–4 to 0–7. This can help schedule work relative to recurring windows or support longer staggered calendars; it does not make a maintenance window itself longer.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
New-CMSchedule `
-Start (Get-Date) `
-DayOfWeek Monday `
-WeekOrder Second `
-RecurCount 1 `
-OffsetDay 6
Confirm the cmdlet and parameter casing in the installed Configuration Manager PowerShell module. Test recurring schedules before using them for production patching.
PXE, BitLocker and Windows 11 deployment
Preferred management point for PXE
PXE clients can contact an initial lookup management point and receive a list of management points for subsequent communication. Configuration Manager can direct clients based on site boundaries and client location, which is useful for distributed organizations with multiple management points or regional datacenters.
Rank #3
- A PREMIUM PERFORMANCE LAPTOP — Ready for work, school, and creativity. Built for busy days, big projects, and nonstop multitasking. Run video calls, school and work apps, 20+ browser tabs, and AI tools at the same time without slowing down.
- WITH AI BUILT IN — With a dedicated AI chip (Qualcomm Snapdragon X2 Elite), this Copilot+ PC[5] on Windows 11 helps you work smarter and faster. Prompt, create, and automate with ease - ready for even your most demanding tasks.
- A 13.8" TOUCHSCREEN YOU'LL ACTUALLY USE — Sharp colors, real detail, smooth 120Hz scrolling on the PixelSense touchscreen[1] with LCD display[2]. Tap, scroll, or pinch to zoom - whichever feels right for streaming, editing photos, or daily work.
- 20 HOURS OF BATTERY (LEAVE THE CHARGER) — Up to 20 hours of video playback[3] on a single charge. Work from a coffee shop, take it to class/work, or binge an entire season on a long flight — it'll keep up.
- THE PORTS YOU NEED — Two USB-C / USB4[4] ports for fast charging, big file transfers, or hooking up to three 4K monitors when you want a full desktop. Wi-Fi 7 keeps you online and fast wherever you are.
Enable PXE on the distribution point and check boundary-group membership and management-point relationships before rollout. Misconfigured boundaries can send clients to an unexpected management point. Validate from each major network segment and review PXE and management-point logs when a boot fails. The 2309 PowerShell updates add preferred-MP parameters to Add-CMDistributionPoint and Set-CMDistributionPoint: PreferredMPEnabled and InitialMPForLookup.
BitLocker recovery-key escrow during provisioning
ProvisionTS can escrow a BitLocker recovery key to the Configuration Manager database during provisioning. That can make recovery information available earlier, but only if the task sequence succeeds, the encryption state is suitable and permissions allow escrow. Verify recovery workflows, database protection and key-rotation behavior; database escrow is not, by itself, a complete enterprise recovery strategy. Compare it with Microsoft Entra ID or Intune escrow according to your management model.
Windows 11 edition-upgrade policy
Configuration Manager can create a policy to upgrade a Windows 11 edition. The target edition and source state must be supported, and the device still needs eligible licensing and a valid activation entitlement or product key. Test activation and restart behavior. An edition upgrade is distinct from a feature update or an in-place operating-system upgrade.
Windows 11 Upgrade Readiness Dashboard
The dashboard provides views of Windows devices by installed feature-update version, helps identify upgrade-ready devices, and supports creating collections for feature-update deployment. Treat it as a planning signal, not a guarantee that a device is ready for your organization. Hardware inventory and compatibility data matter, and separate testing is needed for applications, drivers, firmware, VPN and security agents. Pilot collections before broad deployment.
Cloud Management Gateway changes
Console workflow and existing deployments
The 2309 console improves the web/server application flow for CMG creation by letting administrators select a tenant and application name using tenant information, then proceed through sign-in. For an existing CMG, Microsoft’s documented path to update the web-server application is Administration > Azure Active Directory Tenants > select the tenant > select the server app > Update Application Settings. The 2309 UI and release documentation use “Azure AD”; the service is now called Microsoft Entra ID.
PowerShell workflow
The 2309 release notes add a TenantId parameter to New-CMCloudManagementGateway and document Set-UpdateServerApplication. If the redirect URL has not been updated, CMG creation can fail with a server-application update error. Update the application settings and redirect URL, then set the tenant ID and validate authentication, client communication, content access and cloud-management traffic.
Recommended Free Tools
Set-UpdateServerApplication `
-TenantId "aaaabbbb-0000-cccc-1111-dddd2222eeee"
Replace the example GUID with the actual tenant ID. This is the parameter syntax documented in the 2309 PowerShell release notes; an incomplete form sometimes reproduced elsewhere is not valid syntax. The workflow improves application setup, not every aspect of CMG operation.
Rank #4
- A PREMIUM PERFORMANCE LAPTOP — Ready for work, school, and creativity. Built for busy days, big projects, and nonstop multitasking. Run video calls, school and work apps, 20+ browser tabs, and AI tools at the same time without slowing down.
- WITH AI BUILT IN — With a dedicated AI chip (Qualcomm Snapdragon X2 Elite), this Copilot+ PC[5] on Windows 11 helps you work smarter and faster. Prompt, create, and automate with ease - ready for even your most demanding tasks.
- A 15" TOUCHSCREEN YOU'LL ACTUALLY USE — Sharp colors, real detail, smooth 120Hz scrolling on the PixelSense touchscreen[1] with LCD display[2]. Tap, scroll, or pinch to zoom - whichever feels right for streaming, editing photos, or daily work.
- 19 HOURS OF BATTERY (LEAVE THE CHARGER) — Up to 19 hours of video playback[3] on a single charge. Work from a coffee shop, take it to class/work, or binge an entire season on a long flight — it'll keep up.
- Two USB-C / USB4[4] ports and a microSD card reader for fast charging, big file transfers, or hooking up to three 4K monitors when you want a full desktop. Wi-Fi 7 keeps you online and fast wherever you are.
PowerShell changes in one place
In addition to the cmdlets described above, 2309 adds New-CMWindows11EditionUpgrade. The example below uses a deliberately fictional key; do not place a production key in shared scripts or documentation.
New-CMWindows11EditionUpgrade `
-Name "NewEditionPolicyByKey" `
-WindowsEdition Windows11Enterprise `
-ProductKey "123ab-cd456-789ef-2j3k4-0ghi1"
The release notes also list changes to Invoke-CMScript, New-CMCloudManagementGateway, Add-CMDistributionPoint, Set-CMDistributionPoint and Set-UpdateServerApplication. Check the installed Configuration Manager PowerShell module and permissions before automating production changes.
Upgrade Configuration Manager to 2309
Use the in-console servicing workflow rather than treating the final installation button as the whole upgrade. Microsoft’s update guidance is at Configuration Manager updates and servicing.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall- Complete the readiness checks: confirm the source version is eligible, install ODBC Driver 18.1.0 or later on required servers, check site health and take a site backup.
- In the Configuration Manager console, open Administration > Overview > Updates and Servicing.
- Select the Configuration Manager 2309 update. If it is not downloaded, allow the normal update workflow to download it.
- Select Run Prerequisite Check. Resolve blocking errors and investigate warnings before proceeding.
- Start the update installation and review the feature-selection page. Choose whether clients upgrade directly or first through a pre-production collection.
- Accept the license terms and privacy statements, then complete the wizard.
- Monitor installation status and site-component logs. Do not begin broad client deployment until the site update completes and the site is healthy.
- Upgrade a controlled client pilot, validate the workflows below, then promote the client update to production when results meet your criteria.
For a more detailed walkthrough, see HTMD’s Configuration Manager 2309 coverage. The console remains the production servicing path; an early-ring download script is not a general substitute for it.
Post-upgrade validation
Validate the operations your environment uses, not just the console version. Work through a representative client pilot before widening deployment.
- Confirm console connectivity, site-component health and client policy retrieval.
- Check hardware inventory, reporting, application deployment and software-update deployment.
- Test PXE from major network segments and confirm management-point selection follows boundary design.
- Verify BitLocker key escrow and that authorized staff can retrieve keys using the intended recovery process.
- Check CMG authentication and client communication if the environment uses a gateway.
- Test scheduled scripts against UTC expectations and confirm results; verify supported Logic App notification run details where configured.
Troubleshooting common upgrade and feature problems
The update does not appear in Updates and Servicing
Check source-version eligibility, service connection point health, update synchronization, connectivity to Microsoft update services and successful download. Confirm whether the environment is using an early or production availability ring. Review dmpdownloader.log, hman.log and related update logs. Early-ring instructions were for opt-in availability; they are not the normal production installation method. Historical early-ring context is documented at HTMD’s early-ring guide.
The prerequisite check reports an ODBC problem
Verify that driver 18.1.0 or later is installed on every required site server and remote role, with the appropriate architecture. Follow the driver installer’s service or restart requirements, retain SQL Native Client 11 unless Microsoft guidance says otherwise, and rerun the checker.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- Brilliant Display – Stunning 13.8" PixelSense touchscreen[1], with brilliant LCD display[2], unleashes luminous whites, deeper blacks and colors so richly saturated bringing vivid life into every frame – perfect for work, school, streaming and creative tasks.
- Power that lasts all day – With 20 hours of battery life[3], the new Surface Laptop powers through your entire day, so you can create, work and stream from morning to night without reaching for a charger.
- Work at the speed of your ideas – Built with the latest Qualcomm Snapdragon X2 Elite (12 Core) processors, Surface Laptop delivers fast, AI‑accelerated performance—making it the most powerful Surface laptop for everything from multitasking to demanding workloads.
- The ports you need – Charge on-the-go, transfer data fast, or create the ultimate desktop set up with two USB-C / USB4[4] ports.
- Built-in AI Companion – Work smarter, create freely, and communicate with confidence—Copilot[5] on Windows 11 is always there to help.
A feature appears in the console but does not work on clients
Check that the client update has been deployed and that the target device received policy and the updated client binaries. Site and console updates alone do not provide every client-side capability.
PXE clients select an unexpected management point
Check IP-subnet and VPN boundaries, boundary-group membership, preferred-MP settings, initial lookup configuration, distribution-point PXE settings and management-point availability. Compare behavior across affected network segments and inspect PXE and management-point logs.
BitLocker escrow is missing
Check where ProvisionTS runs in the task sequence, task-sequence context, TPM and encryption state, database permissions and key-rotation behavior. Confirm whether the intended recovery destination is ConfigMgr, Intune or Microsoft Entra ID.
A scheduled script runs at the wrong local time
Recalculate the schedule as UTC for the target region and account for daylight-saving changes. Label UTC explicitly in runbooks and notifications.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →CMG creation reports a server-application error
Update the server application and redirect URL before creating the CMG. Check tenant ID, application permissions, sign-in identity and application registration, then validate the resulting client and cloud traffic.
Fixes and lifecycle considerations
Version 2309 also included maintenance fixes. Microsoft’s 2309 hotfix documentation describes improvements to console memory management beyond the 2-GB virtual-memory range; a site-recovery issue where site-system roles could show critical after recovery to a different drive letter; and fixes involving deleted configuration baselines whose scripts could keep running, inconsistent application-deployment summary counts, Active Directory Group Discovery overwriting Microsoft Entra group-discovery data, content-location requests and apostrophes in adapter or Active Directory site names. It also documents a client setting to reduce network packets for Modern Standby devices, USO components in the client MSI, revisions to BulkRegistrationTokenTool.exe and improvements to the CleanIISLogs scheduled task.
The same hotfix documentation clarifies an Attack Surface Reduction compliance-evaluation issue: applicability and compliance are different. An earlier applicability check could incorrectly report a Server SKU as compliant without enforcement; the correction concerns evaluation, not the introduction of ASR itself.
Version 2309 documentation also warned that configured resource-access policies would block a later 2403 upgrade and advised moving that workload to Intune before January 2024. That was historical release guidance, not a current deadline. Administrators still on 2309 should review current supported-version and deprecated-feature documentation before planning a later upgrade.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsChoosing a path from a 2309-era environment
For an existing Configuration Manager estate, first identify the workloads that depend on on-premises infrastructure: PXE, task sequences, software distribution, application management or datacenter-connected distribution points. Then check current Microsoft support and upgrade guidance rather than choosing 2309 simply because it is familiar.
- Maintain Configuration Manager: appropriate where existing on-premises management, OS deployment and distribution workflows remain necessary, provided the team can operate the infrastructure.
- Use co-management: retain ConfigMgr for selected workloads while moving others to Intune; this requires clear ownership and planning for workload precedence and policy conflicts. See Microsoft’s co-management overview.
- Move toward Intune and Windows Autopilot: consider cloud-native policy and provisioning where the organization can redesign workflows that depend on PXE or traditional task sequences. Intune’s product overview is at Microsoft Intune.
- Use CMG selectively: for an existing ConfigMgr environment that needs internet-based client management, assess cloud dependencies, security and operational costs using Microsoft’s CMG planning guidance.
Configuration Manager remains a product for organizations with a management case for it; an old feature release is not by itself a reason to start a deployment. Microsoft’s product overview is at Microsoft Configuration Manager.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

