jmak Posted February 7, 2019 Posted February 7, 2019 I have W10 1803 clients with Server 16 running WSUS and the clients seem to have stopped picking up updates. In the tool tray I have the warning icon and in Windows Update Settings I have the "Your device is missing important security and quality fixes." warning. It looks like the client is looking to Windows Update on the internet, rather than WSUS, despite the fact it displays "*Some settings are managed by your organisation" and in the explanation shows: "Policies set on your device Intranet Update Service for detecting Updates Auto Reboot will not happen with logged on users Automatic Update options Specifies the hours before checking updates" I've checked RSOP and it shows my policy applying. The settings in my policy are: Windows Components/Windows Update Allow Automatic Updates immediate installation: Enabled Automatic Updates detection frequency Enabled Check for updates at the following interval (hours): 5 Configure Automatic Updates: Enabled Configure automatic updating: 4 - Auto download and schedule the install Install during automatic maintenance Enabled Scheduled install day: 0 - Every day Scheduled install time: 15:00 Do not display 'Install Updates and Shut Down' option in Shut Down Windows dialog box: Enabled No auto-restart with logged on users for scheduled automatic updates installations: Enabled Reschedule Automatic Updates scheduled installations: Enabled Specify intranet Microsoft update service location Enabled Set the intranet update service for detecting updates: http://XXXSRV001.SCHOOL.INTERNAL:8530 Set the intranet statistics server: http://XXXSRV001.SCHOOL.INTERNAL:8530 (Where http://XXXSRV001.SCHOOL.INTERNAL:8530 is the disguised version of our server) I've just seen @Gideon_Kay 's post. Our policy is using http and 8530. Does W10 1803 insist on https or will it do what it's told? TIA
DGardiner Posted February 7, 2019 Posted February 7, 2019 was wsus working before? if so try opening cmd on the wsus server and run iisreset and see if that helps them pull updates, if it starts working again iis probably needs a bit more ram
DavR Posted February 7, 2019 Posted February 7, 2019 We're running WSUS on Server 2012 R2 with Win 10 1803, and we're using regular http without any issue. First thing I would do is make sure you've knobbled all and any connections to online Windows Updates, which is surprisingly difficult to do. It could well be that the missing updates it's flagging are one's you don't want, such as the 1809 upgrade. I've got the following enabled to do that: Do not allow update deferral policies to cause scans against Windows Update Do not connect to any Windows Update Internet locations Do the clients have the updates that you are expecting them to have?
Gideon_Kay Posted February 7, 2019 Posted February 7, 2019 Hi I had to use HTTPS in order to enable 3rd party updates on SCCM. You can still use http on wsus Thanks Gideon 1
jmak Posted February 7, 2019 Author Posted February 7, 2019 I'll try resetting IIS. It was working; it's not now - clients are missing updates that are authorised in WSUS.
jmak Posted February 8, 2019 Author Posted February 8, 2019 Thanks for the suggestions. Unfortunately it's still not working Any other ideas? When I restart my PC, there's nothing there at first and then after a few minutes I get the icon alerting me to missing updates, but no option to download or install anything.
Chuckster Posted February 9, 2019 Posted February 9, 2019 Try the following... 1. Open services.msc and stop the Windows Update service 3. Go to C:\Windows\SoftwareDistribution and delete all the contents within the SoftwareDistribution folder 5. Start the Windows Update service Give it some while and you will begin seeing clients reporting correctly to WSUS and should pull down any missing updates. 1
jmak Posted February 9, 2019 Author Posted February 9, 2019 I'll try that on Monday. It's a widespread problem across the network; assuming it works, is there anything I can push out via GPO?
Jobos Posted February 9, 2019 Posted February 9, 2019 On the clients look at the update history. When was the last successful update? I get the odd client dropping out but never more than one at a time so I would be looking at the server. 1
bigal06 Posted February 13, 2019 Posted February 13, 2019 Mine was working then I broke it by enabling drivers in Windows Updates (GPO). This actually breaks updates from WSUS! I switched it back and all working again. I think it was this one: Computer Configuration/Administrative Templates/Windows Components/Windows Update/Do not include drivers with Windows Updates Setting to Disabled breaks updates from WSUS Setting to Enabled or Not Configured fixes updates from WSUS. 1
jmak Posted February 13, 2019 Author Posted February 13, 2019 I'll try resetting IIS. It was working; it's not now - clients are missing updates that are authorised in WSUS. Authorised, but download to the WSUS server had failed Must try harder.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now