- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-15-2023 06:49 PM
Dear Community,
We are using AnyConnect version 4.XX.XX
We plan to upgrade from old current version to new Secure Client.
There are four latest version of Secure client version ( 5.0.04032, 5.0.03076, 5.0.03072, 5.0.02075 ).
Please kindly recommend which suitable Secure client we can upgrade to?
using SCCM to deploy agent.
Note: We use Win10 and Win11
Thanks for your supporting and advise.
Solved! Go to Solution.
- Labels:
-
Identity Services Engine (ISE)
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-17-2023 06:41 AM
We were able to push out 5.0.04032 using the SCCM with success. At this
point we are not going to try the others. Believe me it was a task! There
are certain GPO’s changes we had to make.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-15-2023 11:24 PM
if i were you i always want to go latest stable version by reading the release notes and compatible with your Gateway :
Note : first i would install manually on the test clients and test all working as expected before role out mass using SCCM.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-16-2023 02:18 AM
Thanks for your commend.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-16-2023 05:10 AM
Yup no reason not to use the latest here.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-17-2023 06:41 AM
We were able to push out 5.0.04032 using the SCCM with success. At this
point we are not going to try the others. Believe me it was a task! There
are certain GPO’s changes we had to make.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-17-2023 07:19 AM
good to know . hope all good ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-24-2023 08:16 PM
Cool
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-20-2023 01:20 AM
During upgrade vai SCCM, we have challenge one things on adding MAC address manaully to client provision. That's the quit challenge for. Hence, could you share your experiences with that?
Remark: In our environment we have around 8K endpoints and the impact is sensitive. So we need to rollout scope by scope.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-20-2023 09:07 AM
@sot01 what do you mean regarding "adding MAC address manaully to client provision"? An endpoint MAC address is not part of an AnyConnect / Secure Client configuration.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-23-2023 04:15 AM - edited 10-23-2023 04:16 AM
Hello @Marvin Rhoads,
Thanks your for your comment.
Our environment have thousand of end points up to 8K. So, the progress of upgrade agent is take times. We need to upgrade phase by phase like 1K endpoints per time. By this if we don't use client provision and set with MAC addresss to scope that numbers. How we could do to archieve that based on your experiences?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-23-2023 04:35 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-23-2023 10:50 PM
Hello @ahollifield,
Kindly fine here.
Current status as below:
We are using Anyconnect version running on 4.XX.XX, with client provisioning setting set to this version and identity group is any.
Objective:
. We would need to upgrade to anyconnect version to secure x version (5), with specific scope of endpoint only (1K endpoints per phase).
. Deployment method, we planned to use SCCM (We already clear for this).
. Client provisioning setting - Unknow (We don't know how to configure or setting on client provisioning).
Could you advise on this? How we could configure or define it phase by phase like we mentioned?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-23-2023 09:06 AM
When we want to do that with SCCM, we just create a group associated with an OU that we place the upgrade candidates into. Divide your computers into however many batches you like and put them all in the target group a batch at a time. No need to sort on MAC addresses - just use computer names.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-23-2023 10:49 PM
Hello @Marvin Rhoads,
Let me share our
Current status as below:
We are using Anyconnect version running on 4.XX.XX, with client provisioning setting set to this version and identity group is any.
Objective:
. We would need to upgrade to anyconnect version to secure x version (5), with specific scope of endpoint only (1K endpoints per phase).
. Deployment method, we planned to use SCCM (We already clear for this).
. Client provisioning setting - Unknow (We don't know how to configure or setting on client provisioning).
Could you advise on this? How we could configure or define it phase by phase like we mentioned?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-24-2023 06:50 AM
@sot01 when you say "...client provisioning setting set to this version and identity group is any", what system are you referring to? These are not AnyConnect settings.
