LCM Basics
The Local Configuration Manager (LCM) is the core component of PowerShell Desired State Configuration (DSC) that ensures nodes adhere to their desired configuration. It manages the application of configurations, monitors compliance, and enforces remediation when deviations occur. Proper LCM configuration is essential for reliable DSC operations, as it dictates how configurations are applied, how compliance is tracked, and how the system responds to changes.
LCM Configuration Settings¶
The LCM is configured using the Set-DscLocalConfigurationManager cmdlet. Key settings include:
1. ConfigurationMode¶
Determines how the LCM enforces desired states: - ApplyAndMonitor: Applies the configuration immediately and monitors for drift (default). - Audit: Only audits the current state without making changes. - ApplyOnly: Applies the configuration once and does not monitor for drift.
2. RefreshMode¶
Controls how often the LCM checks for configuration changes: - Pull: The LCM pulls configurations from a pull server (requires a configuration repository). - Push: The LCM applies configurations pushed from another node (less common).
3. RebootNodeIfRequired¶
Automatically reboots the node if a configuration requires it (e.g., after installing updates).
4. ConfigurationModeFrequencyMins¶
Specifies how often the LCM checks for configuration drift (in minutes). Applies only to ApplyAndMonitor mode.
5. ReportPath¶
Defines the location where LCM generates compliance reports (e.g., for audit or apply modes).
Applying LCM Configuration¶
After defining settings, use Set-DscLocalConfigurationManager to apply them. The LCM configuration is stored in the registry at HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\DSC.
Set-DscLocalConfigurationManager -ConfigurationMode ApplyAndMonitor `
-ConfigurationModeFrequencyMins 60 `
-ReportPath "C:\DSCReports" `
-RebootNodeIfRequired $true
For pull mode, ensure the LCM is configured to connect to a pull server by specifying the ConfigurationRepositoryWeb parameter.
Key Takeaways¶
- The LCM enforces desired states and monitors compliance.
- Use
Set-DscLocalConfigurationManagerto configure settings likeConfigurationModeandRefreshMode. ApplyAndMonitoris the default mode for continuous compliance checks.RebootNodeIfRequiredensures automatic reboots for critical configurations.- Reports and logs are stored in the
ReportPathdirectory for troubleshooting.