Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

SOLVED SCCM not deploying updates

  • Thread starter Thread starter wideth
  • Start date Start date
  • Replies Replies 6
  • Views Views 11K
Status
Not open for further replies.

wideth

New Member
Messages
4
Reaction score
0
Points
1
The SCCM server doesn't deploy updates. WSUS Downloads them and you can view the updates in the ADR deployment but all the Client computers show an unknown status. I haven't been able to figure out how to make all the clients give a non unknown status. As far as I can see all the clients are communicating with the SCCM server. The WSUS settings point to the SCCM server in the registry but the updates just don't install. I have also seen on a few machines we recently reimaged that SCCM doesn't seem to run post-deployment task sequences. So software like our antivirus and a few other programs we use don't ever get deployed. Any assistance is greatly appreciated.
 
Can you tell us how are you deploying the updates ?. Have you checked if the updates are applicable to the client computers ?.
 
Thankyou for your time. We have an ADR that downloads the updates and deploys them. Our site only has windows 10 PCs either 1803 or 20h2. When I set WSUS up I downloaded all the WIndows 10 updates as well as all the servers we have on our site. The updates are in a pending ADR group waiting to be deployed. Having done further troubleshooting I now see another error when I check for updates. Some update files aren't signed correctly. Error code: (0x800b0109). Doing some searching it appears that I may have a certificate problem but I have checked in IIS (and redone another self signed one). I am not sure what to try next.

Many thanks
 
Please note that Windows 10 1803 has already reached its end of support, you have to upgrade those machines ASAP to still supported.

For 20H2 machines, did you check the related client log files?
  • ScanAgent.log
  • UpdatesStore.log
  • UpdatesDeployment.log
  • UpdatesHandler.log
  • WUAHandler.log
 
Good afternoon. Many thanks for your reply. Sorry I meant 1909 not 1803. I have the logs and I am also looking at a tool Solarwinds has that diagnoses WSUS. By the looks of it. I have a problem with the proxy and an invalid iuident.cab url.
 

Attachments

Check if you are using any proxy either in the SUP and the client side. Check also the SSL certificate for the SUP.
 
Solution
Thank you for your help. It is looking better than it did. my updates now say non-compliant 595 compliant 4 and unknown 195. (it was previously fully non-compliant. Hopefully, over the next few days, it will start pushing them out in the maintenance window to more machines.
 
Status
Not open for further replies.

Forum statistics

Threads
7,172
Messages
27,993
Members
18,297
Latest member
Kahnrym

Trending content

Back
Top