ITGURU Posted February 20, 2022 Posted February 20, 2022 I have inherited a site which runs SCCM for Windows Updates. It seems very complex just to setup update deployments and testing updates on 1 machine, and doesnt seem to be working as expected. Can I remove the role entirely from the SCCM server, spin up another VM, and install/use WSUS as I do at other sites by creating a new GPO to point clients to the new server, let them check in, and them approve through the WSUS console, so i can then manage all sites from a single console. thanks.
Steve21 Posted February 20, 2022 Posted February 20, 2022 Can you? yes (You wouldn’t even need to uninstall it as the GPO would override the SCCM client config as that uses local gpo) Should you? hell no! Sccm is much more powerful than WSUS and requires no real maintenance at all for updates once it’s setup Is there something specific you have issues with? Steve
ITGURU Posted February 20, 2022 Author Posted February 20, 2022 Yes, I've created a group with the updates in, deployed it to a client group, but when do a check for updates on the client, it doesnt pick up the updates even after forcing a wuault /reportnow it just says up to date once created deployment how long does it take for client to find updates? with standard WSUS console management, i can approve an update, do a force checkin and it'll find and download/install the updates immediately.
Steve21 Posted February 20, 2022 Posted February 20, 2022 SCCM doesn’t use the check for updates part, it uses its client, so it wouldn’t ever show if you’re just checking in there. Same with wauclt that’s legacy In terms of timings that depends what you have setup in SCCM for the check in of the clients, if it’s scanning every hour or day etc If you open Software centre is it showing it’s detected them? Steve
ITGURU Posted February 20, 2022 Author Posted February 20, 2022 ahh this is the first time i've used SCCM. I've re-checked for compliance and no, no updates showing.
Steve21 Posted February 20, 2022 Posted February 20, 2022 It's not in compliance. That's settings. SCCM has loads of bits it can do, each have different areas. In control panel, open up Configuration Manager, and re-run the two actions: Machine Policy retrieval and then Software Update Scan Cycle Basically will force it to check now, ignoring any timing/settings you have currently If it's still not finding anything after a few minutes it's most likely some setting is wrong on the server/client config Steve
ITGURU Posted February 20, 2022 Author Posted February 20, 2022 All updates have a black cross against then - when try to download it says all software udpates in this selection have expired or meta-data only, and cannot be downloaded
Steve21 Posted February 20, 2022 Posted February 20, 2022 That's in the console on the server I assume you mean, rather than the client? If so it sounds it like it's never actually been setup to work properly. Black crosses are expired, but they'd only expire once they've been superseeded (yellow) and then on a few months later etc. Honestly if nothings been setup properly yet, just have a flick through a guide online, it should only take 15-20 minutes to setup a basic SCCM for updates to deploy without anything fancy being setup. Even if you do a GPO to point to WSUS for now, and play with SCCM on a client you'd soon stop using WSUS when you have SCCM working Steve
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now