WSUS Server Not Downloading Windows 11 updates since March 2023

Rob Harradine 0 Reputation points
2023-12-20T16:57:15.79+00:00

We have had a couple of Windows 11 computers on our domain for a year or so and have just replaced a number of our old Win 10 units with new hardware running Win 11. I have noticed that these PC's are reporting in as Up to Date from WSUS. Initially we thought that the clients were at fault and updated ADMX/GPO's however having looked further it would appear as though the update downloads are not completing on the WSUS server.

From our observations it looks like the downloads are starting but as they get to 100% appear to get stuck. Looking at the security updates section it is the Cumulative Updates for Windows 11 Version 22H2 that are failing to download. All other updates appear to be downloading OK. I have updating the MIME types in IIS and performed an IIS restart.

In the event viewer Application log I'm seeing Event 10032 (The server is failing to download some updates) and Event 364 (Content download failed. Reason: File cert verification failure).

Server is Windows Server 2012R2. I can appreciate that this is now an unsupported OS however the updates have been failing since March.

Any help would be greatly appreciated. Thanks.

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,760 questions
Windows Server 2012
Windows Server 2012
A Microsoft server operating system that supports enterprise-level management, data storage, applications, and communications.
1,532 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,159 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Adam J. Marshall 8,706 Reputation points MVP
    2023-12-20T21:26:27.8266667+00:00

    See: https://www.ajtek.ca/wsus/client-machines-not-reporting-to-wsus-properly/#WSUSCheckHealth

    and the one right below it.

    Perform the checkhealth and also the reset and report back if that fixes it and/or reveals anything else.

    You also may need

    https://www.ajtek.ca/wsus/wsus-bits-foreground-priority-mode-vs-background-priority-mode/


  2. Adam J. Marshall 8,706 Reputation points MVP
    2023-12-21T14:16:22+00:00

    Do you have the UUP mimetypes setup?

    https://www.ajtek.ca/guides/how-to-prepare-for-on-prem-wsus-uup-updates/

    You can try declining the updates, running the Server Cleanup Wizard (SCW) and then re-approving the updates.