How to repair unhealthy Endpoint Manager SUP role? Clients unable to receive updates

Charlie Dobson 1 Reputation point
2020-10-22T02:09:13.963+00:00

I'm managing an Endpoint Manager Current Branch (2002) environment. I had everything setup so that clients could get updates while on the internal network/VPN. With COVID and work-from-home, my company asked me to setup an external SUP so that users don't have to connect to VPN to get updates.

I setup an external server on our DMZ and confirmed clients could communicate with it over SSL / WSUS port 8531. However, when I added the WSUS feature to the server, I failed to point the update content location to the shared path on the primary SUP server. This ran for a little while until I noticed clients complaining about SOAP issues and getting 0x80244010, 0x80244007, & 0x8023300d (on different endpoints) errors.

After noting my mistake on the external server, I ran WSUSUTIL.EXE movecontent \\primarysup\wsus -skipcopy and the output said it was successful. I've verified my SQL Server 2012 database is showing the correct path by running Select LocalContentCacheLocation from tbConfigurationB. However, my clients are still reporting the above errors and are basically pounding my primary SCCM server with requests causing high CPU usage.

Is there a step I'm missing to fix the endpoints? Or did I hose my database and need to uninstall and re-install SUP roles on all servers?

Microsoft Security | Intune | Configuration Manager | Updates
{count} votes

1 answer

Sort by: Most helpful
  1. Amandayou-MSFT 11,156 Reputation points
    2020-10-23T06:58:46.923+00:00

    Hi @Charlie Dobson ,

    -->However, when I added the WSUS feature to the server, I failed to point the update content location to the shared path on the primary SUP server.

    It seems that we could install the secondary SUP on the SCCM console instead of adding the WSUS feature to the server.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.