Jump to content

Recommended Posts

Posted

I have W10 1803 clients with Server 16 running WSUS and the clients seem to have stopped picking up updates. In the tool tray I have the warning icon and in Windows Update Settings I have the "Your device is missing important security and quality fixes." warning. It looks like the client is looking to Windows Update on the internet, rather than WSUS, despite the fact it displays "*Some settings are managed by your organisation" and in the explanation shows:

"Policies set on your device

Intranet Update Service for detecting Updates

Auto Reboot will not happen with logged on users

Automatic Update options

Specifies the hours before checking updates"

 

I've checked RSOP and it shows my policy applying. The settings in my policy are:

 

Windows Components/Windows Update

 

Allow Automatic Updates immediate installation: Enabled

Automatic Updates detection frequency Enabled

Check for updates at the following interval (hours): 5

Configure Automatic Updates: Enabled

Configure automatic updating: 4 - Auto download and schedule the install

Install during automatic maintenance Enabled

Scheduled install day: 0 - Every day

Scheduled install time: 15:00

Do not display 'Install Updates and Shut Down' option in Shut Down Windows dialog box: Enabled

No auto-restart with logged on users for scheduled automatic updates installations: Enabled

Reschedule Automatic Updates scheduled installations: Enabled

Specify intranet Microsoft update service location Enabled

Set the intranet update service for detecting updates: http://XXXSRV001.SCHOOL.INTERNAL:8530

Set the intranet statistics server: http://XXXSRV001.SCHOOL.INTERNAL:8530

 

(Where http://XXXSRV001.SCHOOL.INTERNAL:8530 is the disguised version of our server)

 

I've just seen @Gideon_Kay 's post. Our policy is using http and 8530. Does W10 1803 insist on https or will it do what it's told?

 

TIA

Posted

was wsus working before? if so try opening cmd on the wsus server and run iisreset

 

and see if that helps them pull updates, if it starts working again iis probably needs a bit more ram

Posted

We're running WSUS on Server 2012 R2 with Win 10 1803, and we're using regular http without any issue.

 

First thing I would do is make sure you've knobbled all and any connections to online Windows Updates, which is surprisingly difficult to do. It could well be that the missing updates it's flagging are one's you don't want, such as the 1809 upgrade.

 

I've got the following enabled to do that:

  • Do not allow update deferral policies to cause scans against Windows Update
  • Do not connect to any Windows Update Internet locations

 

Do the clients have the updates that you are expecting them to have?

Posted

Thanks for the suggestions. Unfortunately it's still not working :confused2:

 

Any other ideas? When I restart my PC, there's nothing there at first and then after a few minutes I get the icon alerting me to missing updates, but no option to download or install anything.

Posted

Try the following...

 

1. Open services.msc and stop the Windows Update service

3. Go to C:\Windows\SoftwareDistribution and delete all the contents within the SoftwareDistribution folder

5. Start the Windows Update service

 

Give it some while and you will begin seeing clients reporting correctly to WSUS and should pull down any missing updates.

  • Thanks 1
Posted
I'll try that on Monday. It's a widespread problem across the network; assuming it works, is there anything I can push out via GPO?
Posted

On the clients look at the update history. When was the last successful update?

 

I get the odd client dropping out but never more than one at a time so I would be looking at the server.

  • Thanks 1
Posted

Mine was working then I broke it by enabling drivers in Windows Updates (GPO). This actually breaks updates from WSUS! I switched it back and all working again.

 

I think it was this one:

 

Computer Configuration/Administrative Templates/Windows Components/Windows Update/Do not include drivers with Windows Updates

Setting to Disabled breaks updates from WSUS

Setting to Enabled or Not Configured fixes updates from WSUS.

  • Thanks 1
Posted
I'll try resetting IIS.

 

It was working; it's not now - clients are missing updates that are authorised in WSUS.

 

Authorised, but download to the WSUS server had failed :doh:

 

Must try harder.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...