Gongalong Posted May 14, 2017 Posted May 14, 2017 Hi folks, I have a problem with WSUS inconsistently listing PCs. I'm using WSUS 6.3.9600.16384 on a 2012 R2 server, in a domain with about 500 Win7 and 10 PCs. The PCs are pointed at WSUS using Group Policy. The specific issue I have is that only around half the PCs are listed in WSUS (under Computers > All Computers). If I check the WindowsUpdate.log of a missing Win 7 PC, it seems to be quite happily getting updates from the WSUS server. If I stop the Windows Update service, delete the WindowsUpdate.log, restart the Windows Update service, and run Windows Update, the PC then seems to appear in WSUS. It's inconsistent though, as I had one PC appear, then disappear again. Can anyone advise on what could be wrong, or where to troubleshoot? Thanks
FN-GM Posted May 14, 2017 Posted May 14, 2017 (edited) Did you sysprep the image on these computers? This kind of issue can we down to a duplicate SusClientId. Try running this on a problem client to see if it helps https://community.spiceworks.com/scripts/show/613-cloned-machines-not-reporting-into-wsus-server Edited May 14, 2017 by FN-GM 1
Gongalong Posted May 14, 2017 Author Posted May 14, 2017 No. Some would have been ghost'd, but SID should have been changed via a Ghost utility. None of our Win 10 PCs are imaged (yet), and some of those are missing also.
3s-gtech Posted May 14, 2017 Posted May 14, 2017 We sysprep, but I still have to run a script which resets the WSUS ID on each machine otherwise only one PC of that image will appear. This can be done via your sysprep unattend or using GP after deploying. 1
Gongalong Posted May 14, 2017 Author Posted May 14, 2017 Is a WSUS ID different from a SID? I spotted this about resetting a WSUS ID https://gallery.technet.microsoft.com/scriptcenter/Reset-WSUS-Authorization-2e26d1b0
Gongalong Posted May 14, 2017 Author Posted May 14, 2017 I used PSGETSID to check some of the PCs in question, and the SIDs are different.
Gongalong Posted May 14, 2017 Author Posted May 14, 2017 Resetting the WSUS ID has caused them to appear in WSUS, albeit they haven't reported yet. I'll give it some hours and check again.
3s-gtech Posted May 14, 2017 Posted May 14, 2017 Odd isn't it? Didn't encounter it until W7, thankfully the fix is simple. I have the GPO ready to apply whenever I image a suite. 1
Gongalong Posted May 14, 2017 Author Posted May 14, 2017 Should the batch file work as a startup script? I've tried it in a GPO, but doesn't seem to be taking effect.
3s-gtech Posted May 14, 2017 Posted May 14, 2017 Yes. Not much more to it - https://blogs.msdn.microsoft.com/jjameson/2011/04/25/script-to-reset-wsus-for-syspreped-image/ 1
Gongalong Posted May 15, 2017 Author Posted May 15, 2017 It needs admin privs to run, when done manually, but presumably a GPO Startup script runs at admin level? From what I've read it should. I did run it manually on 30 or so PCs and had mixed success getting them to register. The first few all appeared straight away, but others haven't. Odd.
FN-GM Posted May 15, 2017 Posted May 15, 2017 A start-up script will be ok, but you might it won't run if the machines are booting quicker than the network is connecting. More of an issue with SSD's these days. A shutdown script would be more reliable but would mean a full reboot is needed for it to run. 1
Gongalong Posted May 15, 2017 Author Posted May 15, 2017 Yep, these are SSD based machines, so sounds like that could be the issue. I'll try as a Shutdown script.
Gongalong Posted May 15, 2017 Author Posted May 15, 2017 Shutdown not working either. Presumably the scope needs to be just the affected PCs, I don't need to add Authenticated Users or any other form of user group? I've seen mention of doing this via a registry edit in GPO also, as that's essentially what it's doing, so will give that a whirl.
jmak Posted May 24, 2017 Posted May 24, 2017 Shutdown not working either. Presumably the scope needs to be just the affected PCs, I don't need to add Authenticated Users or any other form of user group? I've seen mention of doing this via a registry edit in GPO also, as that's essentially what it's doing, so will give that a whirl. @Gongalong: Did you get this fixed? I am doing this manually, but would like to automate it. TIA
Gongalong Posted May 24, 2017 Author Posted May 24, 2017 I did a bunch manually, but have just tried again with a Shutdown script and got it to work. Not sure if any of these were related to getting it working: 1. The script I was using had "pause" at the end. I took that out as it was causing machines to essentially freeze when shutting down. 2. It does require Windows Update to run to update WSUS, and that doesn't happen immediately of course after the machines startup. I tested manually by shutting a PC down, starting up, and running Windows Update. The machine then appeared in WSUS. 3. I'm not sure if it had to be in the scope, but the GPO was definitely working with Authenticated Users only. I added a scope of the affected PCs. I'm waiting a few days for these PCs to be used, and then I will check if given some normal usage the rest have updated. I've spotted a few have already. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now