Hi,
Yes, it is possible to manage systems, including Windows updates and software updates, using SCCM for clients that are not part of an Active Directory domain. This setup is often referred to as managing workgroup clients.
Here are some key points on how this works:
Client Installation: You cannot use the client push installation method for workgroup computers. Instead, you need to manually install the SCCM client on these devices
Communication: Workgroup clients cannot locate management points from Active Directory Domain Services. Instead, they use DNS, WINS, or another management point
Internet-Based Management: SCCM provides options to manage clients over the internet without requiring a VPN connection. This can be done using a Cloud Management Gateway or Internet-based client management
For more detailed information, you can refer to the following resources:
Managing Workgroup (Non-Domain) Clients With Configuration Manager