Sheridan Posted April 15 Posted April 15 (edited) Anyone else used SCCM to deploy April 2026 updates? All of my test groups have failed (all working fine last month!) with the same errors: 0X80D02002 - Delivery Optimization: Download of a file saw no progress within the defined period. In the test clients DeltaDownload log there is a repeating error: HttpSendResponseEntityBody failed with error 5. Correlation vector:q1oHjpbrJE299Q14.9.0.0.6.1.1.3.23.1.4, Failed to send HTTP Response. Error=800704cd Correlation vector:q1oHjpbrJE299Q14.9.0.0.6.1.1.3.23.1.5, Sending Response status code:504 with reason = Gateway timeout All updates are deployed from the SCCM server so I'm not sure if the gateway timeout error is a false flag, and nothing has changed since everything worked perfectly last update run! Oddly the client CMBitsManager log seems to show a successful download but the file size is zero Total Files: 1, Transferred Files: 0, Total Bytes: 0, Transferred Bytes: 0 For CMBITS job {982E1041-76C1-4856-B1D2-0351DD2B6C5B}, CTM job {35297A02-9EEF-4292-BE7F-AFE657CC7002} entered phase CCM_DOWNLOADSTATUS_DOWNLOAD_SUCCESSFUL Edited April 15 by Sheridan
Sheridan Posted April 16 Author Posted April 16 Weirdly I can still deploy applications, but any form of Windows Update, on any PC fails. Typical of SCCM to self destruct like this Looks like moving to Intune is the only way forward, MS obviously don't want us using SCCM anymore
jthompson Posted April 16 Posted April 16 1 hour ago, Sheridan said: Looks like moving to Intune is the only way forward, MS obviously don't want us using SCCM anymore Shifting to using WUfB (with Delivery Optimisation doing p2p where appropriate for your environment) would give SCCM fewer things to annoy you about. 1
Sheridan Posted April 16 Author Posted April 16 I guess this is forcing my hand down the intune route anyway - we're hybrid already so its the next logical step Just have to create a few groups for update rings and I can say goodbye to sccm and its flakey patch management!
CB11 Posted April 16 Posted April 16 Hi, Glad we're not the only ones experiencing this issue! All server, .Net & Workstation updates all fail with the same error as you have been getting 0X80D02002. Office updates and the malicious software removal tool install as expected which is strange. Been here most of the day trying to unpick it through the useless logs! Pulling our hair out!
Sheridan Posted April 17 Author Posted April 17 17 hours ago, CB11 said: Hi, Glad we're not the only ones experiencing this issue! All server, .Net & Workstation updates all fail with the same error as you have been getting 0X80D02002. Office updates and the malicious software removal tool install as expected which is strange. Been here most of the day trying to unpick it through the useless logs! Pulling our hair out! Its not the first time MS have sent out an update that fails, but I'm fed up of diagnosing CM issues every few months so WUfB is my next step!
gcit Posted April 17 Posted April 17 We also had this issue this month, and I think we found the cause. Are you running Sophos Endpoint? We disabled these settings in Sophos, and the errors in DeltaDownload.log disappeared and the downloads in SCCM client worked. Not ideal but a workaround until Sophos can fix this issue: 1 1
Sheridan Posted April 20 Author Posted April 20 On 17/04/2026 at 10:25, gcit said: We also had this issue this month, and I think we found the cause. Are you running Sophos Endpoint? We disabled these settings in Sophos, and the errors in DeltaDownload.log disappeared and the downloads in SCCM client worked. Not ideal but a workaround until Sophos can fix this issue: Yes, we use Sophos and have those enabled, strange its just become an issue this month as we've had CM and Sophos for years However its prompted me to move updates over to Intune and I'm 60% of the way to moving all devices over there. I've had too many issues with CM and updates recently so maybe this will work better and I can just monitor it for the occasional failure! 1
dhallam Posted April 20 Posted April 20 We are also having the same issues with only a few Updates this month, and we also have Sophos. But the above fix in Sophos is not working for us and even with those disabled for an entire room for testing its still getting the error. Strangely if i log onto the computers as the SCCM_Push account and Roll the update in Software Centre i get the error, but if i login as a domain admin and manually run the update in Software Centre it downloads and installs fine. Im going to do some more testing Today and see if i can narrow it down. But for us the office updates are working fine 😖
BOOT Posted April 20 Posted April 20 Hasn't worked for me since Windows 11 launched. Windows 10 still works flawlessly.
gcit Posted April 20 Posted April 20 There is a special hotfix Sophos version, you need to ask Sophos Support for it. (Endpoint FTS 2025.2.3.43.2-SPECIAL-66547) 1
Gdog Posted April 20 Posted April 20 24 minutes ago, gcit said: There is a special hotfix Sophos version, you need to ask Sophos Support for it. (Endpoint FTS 2025.2.3.43.2-SPECIAL-66547) Exactly same problem here, Weirdly March updates still deploy fine just not April. Do you have any details on this Sophos update, I am interested to hear what they say. When i tried manually disabling web scanning on one device it didn't make any difference. Not sure if it would need turning off top level on all machines for it to work.
MYK-IT Posted April 20 Posted April 20 May not related to your specific issue at all, but it does to the April 2026 update itself. Quote Microsoft has released out-of-band (OOB) updates today, April 19, 2026, to address issues introduced by the April 2026 Windows security update. A limited number of Windows Server 2025 devices might experience failures installing the April 2026 security update (KB5082063). In addition, some versions of Windows Server may experience domain controllers restarting repeatedly after installing the April 2026 security update. To address these issues, Microsoft has released OOB updates for the Windows Server versions listed below. Note: The Windows Server 2025 OOB update (KB5091157) addresses both the installation failure issue and the domain controller restart issue. OOB updates released for other supported Windows Server versions address only the domain controller restart issue. For complete guidance and installation instructions, see the relevant KB articles: Standard Windows updates Windows Server 2025: KB5091157 (OS Build 26100.32698) Out-of-band Windows Server, version 23H2: KB5091571 (OS Build 25398.2276) Out-of-band Windows Server 2022: KB5091575 (OS Build 20348.5024) Out-of-band Windows Server 2019: KB5091573 (OS Build 17763.8647) Out-of-band Windows Server 2016: KB5091572 (OS Build 14393.9062) Out-of-band Windows hotpatch updates Windows Server 2025 Datacenter: Azure Edition: Hotpatch KB5091470 (OS Build 26100.32704) Out-of-band Windows Server 2022 Datacenter: Azure Edition: Hotpatch KB5091576 (OS Build 20348.5029) Out-of-band 1
Gdog Posted April 21 Posted April 21 Sophos also fixed it for us, cheers for the pointers guys. Here is their Support Article if it helps anyone else - RESOLVED Advisory: Software using loopback/localhost connections may encounter issues after update 1 1
Reaper Posted April 28 Posted April 28 Thank you to all who spotted this and found the Sophos solution. I've been banging my head against the proverbial wall since last week. Installed the Sophos update and my test client instantly started downloading. Thanks! 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now