FN-GM Posted September 14, 2020 Posted September 14, 2020 Hello, I am having trouble with some computers (82) being stuck in the Active/Passed state and not installing any Windows updates. They are completely ignoring the presence of the updates I have deployed. Some computers (in the same boundary) are fine. I can't see any noticeable difference between computers that do work and those that do not. They have even been built with the same image. Deploying applications and packages works as expected. We are running Windows 10 1909 & SCCM 1910 on Server 2019. We have a single SCCM site server with multiple distribution points located at different physical sites. I checked WUAHandler.log on a problem computer and this is the contents. (I know the log is old - its been an long standing issue) I have noticed that the registry settings in the below location for WSUS are not populated on the problem machines.HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\ Manually entering these registry settings doesn't resolve the issue. I was wondering if anyone have any thoughts please? Thanks for the help.
free780 Posted September 14, 2020 Posted September 14, 2020 Check the date stamp on "C:\Windows\System32\GroupPolicy\Machine\Registry.pol". I think its should be the date the last time local group policy was changed (SCCM client uses local group policy). I've seen AppLocker rules not update when this file is stale (which means its linked to non-local group policy as well). You could try Stopping the wuauserv service rename the c:\Windows\softwareDistribution. Start the Service and try again.
FN-GM Posted September 14, 2020 Author Posted September 14, 2020 Check the date stamp on "C:\Windows\System32\GroupPolicy\Machine\Registry.pol". The modified dates are today. I know group policy is working as recent changes have been applied ok. You could try Stopping the wuauserv service rename the c:\Windows\softwareDistribution. Start the Service and try again. I have tried this and will report back.
FN-GM Posted September 14, 2020 Author Posted September 14, 2020 I have tried this and will report back. It didn't work
FN-GM Posted September 16, 2020 Author Posted September 16, 2020 Does anyone else have any thoughts please?
mdrabble Posted September 16, 2020 Posted September 16, 2020 No idea if will work but how about removing client from sccm and when the client next reports in, sccm will re add it. I assumed when a client is removed any previous/historical data is also removed so would that mean It would redo checks for updates etc?
FN-GM Posted September 16, 2020 Author Posted September 16, 2020 (edited) No idea if will work but how about removing client from sccm and when the client next reports in, sccm will re add it. I assumed when a client is removed any previous/historical data is also removed so would that mean It would redo checks for updates etc? I will try this! Edited September 16, 2020 by FN-GM
FN-GM Posted September 16, 2020 Author Posted September 16, 2020 Or the SSU needs updating first. How do you mean please?
FN-GM Posted September 16, 2020 Author Posted September 16, 2020 Deleting the client didn't make a difference.
mdrabble Posted September 16, 2020 Posted September 16, 2020 Have you checked the WSUS pool in IIS? https://thetechl33t.com/2017/03/29/wsus-app-pool-crashes-with-sccm-syncronization/
FN-GM Posted September 16, 2020 Author Posted September 16, 2020 Have you checked the WSUS pool in IIS? https://thetechl33t.com/2017/03/29/wsus-app-pool-crashes-with-sccm-syncronization/ I did have issues with that when I set it all up. Its stable and running. I went through the wizard and clean it up WSUS.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now