clareq Posted February 5, 2016 Posted February 5, 2016 I'm very confused - not unusual, I know. Our WSUS server is showing that our computers (both Windows 7 and Windows 10) have, in the main, never reported back. Some have, and there is no consistency between those which have and those which have not. The last contact date however is today, and all machines are receiving updates. There are no errors in the WindowsUpdateLog, and all permissions on the server in IIS and file system are correct. Help!!
Steve21 Posted February 5, 2016 Posted February 5, 2016 First question would be are you using WSUS rather than SCCM? As we found they don't report directly back to WSUS if using the SCCM via WSUS Also is this a new thing or has it only started recently? Only reason I ask is we had this at a primary we took over before, and because the GUIDs on the machines weren't cleaned right they were all reporting back as one device. Steve
clareq Posted February 5, 2016 Author Posted February 5, 2016 I'm using WSUS - SCCM didn't seem to update the clients. It seems easier and faster to revert to WSUS than try and continue troubleshooting SCCM. It isn't a new thing - how would we clean a GUID to test?
Steve21 Posted February 5, 2016 Posted February 5, 2016 Check this ID on a few clients and see what it is: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate - SusClientId Steve
clareq Posted February 5, 2016 Author Posted February 5, 2016 Checking that on the two machines I have in front of me, neither of which update, and they are different.
Steve21 Posted February 5, 2016 Posted February 5, 2016 Checking that on the two machines I have in front of me, neither of which update, and they are different. How many pcs do you have roughly? Just in terms of likely of same image/model/build? (Those 2 might not have same, but still same as one that's reported) If you want to manually test one quickly do this: Stop the automatic service Delete the SUSclientID reg key Restart the automatic service Run wuauclt /resetauthorization /detectnow Run wuauclt /reportnow Check back in 30 or so and see if it's come to life Steve
clareq Posted February 5, 2016 Author Posted February 5, 2016 We have about 1500 machines, but my two are unique models. I'll give your suggestion a go now.
clareq Posted February 5, 2016 Author Posted February 5, 2016 My test machine has contacted the server, according to the last contact datestamp, but still has not yet reported.
sted Posted February 5, 2016 Posted February 5, 2016 check the d:\wsus (or wherever the files are permissions) network service needs full control and users needs read
round2it Posted February 5, 2016 Posted February 5, 2016 Mine are doing the same so your not alone. all machines sysprepped prior to imaging. just dont have the time to investigate.
disk Posted February 5, 2016 Posted February 5, 2016 Are you running Deep Freeze per chance? Deep Freeze, after a certain version, allowed you to control updates through Deep Freeze during a maintenance window. It would download, cache, and then install updates from your WSUS (if so configured). It would not show any update activity though. You had to check the Deep Freeze update log to see which updates had been installed. I think they may have fixed that recently though. SolarWinds has a free WSUS client diag tool that might be of some use to you. FREE WSUS Client Diagnostics Tool | SolarWinds
clareq Posted February 5, 2016 Author Posted February 5, 2016 No deep freeze, and the solarwinds tool came back with a proxy error that the solarwinds site said was nothing to worry about
clareq Posted February 17, 2016 Author Posted February 17, 2016 Built a new WSUS server and it's all working.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now