SUP and Boundary Groups

Matt Dillon 437 Reputation points
2021-05-20T18:35:01.463+00:00

I'm questioning my knowledge of how SCCM and Software Updates work. Need some clarification.

I have a primary site set up with PKI certificates - lets call it PRIMARY with MP role and SUP role. It is not set up with the DP role. I setup Windows Updates with SSL and Windows 10 updates are configured and downloading properly from Microsoft.

I have 2 remote site servers- SITE2 and SITE3. These are servers that have the Distribution Point Role setup on them. I also have a CMG setup

I have 4 Boundaries - MAIN, SITE2, SITE3, and VPN

I have 4 boundary groups - MAIN, SITE2, SITE3 and CMG. The primary site server is assigned to the MAIN boundary group, SITE2 is assigned to the SITE2 Boundary group, SITE3 is assigned to the SITE3 boundary group, and all VPN connections point to the CMG (as requested by my boss)

Since the Software Update Point is assigned to only PRIMARY, do I need to add PRIMARY to the remaining Boundary Groups for the endpoints to receive updates? I don't think I do. I think that because the software updates are set up on the Primary and distributed to the remote Distribution Points, that is all I need to do for endpoints to get Windows Updates. Am I on the right track?

Microsoft Configuration Manager Updates
Microsoft Configuration Manager Updates
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Updates: Broadly released fixes addressing specific issue(s) or related bug(s). Updates may also include new or modified features (i.e. changing default behavior).
1,127 questions
0 comments No comments
{count} votes

Accepted answer
  1. Amandayou-MSFT 11,156 Reputation points
    2021-05-21T03:08:16.98+00:00

    Hi @Matt Dillon

    do I need to add PRIMARY to the remaining Boundary Groups for the endpoints to receive updates?

    First of all, we should check if these clients from SITE2, SITE3 and CMG need to receive the update, if not, it is not necessary to configure it.

    If yes, we should add SUP to boundary groups of SITE2, SITE3 and CMG. Is MP shared between PRIMARY with SITE2, SITE3 and CMG? If yes, we just add primary site to SITE2, SITE3 and CMG. If not, we should add new SUP to SITE2, SITE3 and CMG.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.