Office 365 updates not anymore visible in SCCM console

LuisOLI 96 Reputation points
2021-07-20T20:03:20.627+00:00

Hi,

we have a primary site SCCM v2006 with the role WSUS 4.0 installed on a w2012 R2 server.
The problem is that the last time we've got Office 365 updates in SCCM console was for the patch tuesday may 11 2021.
Since then, at each SCCM full synchronization, we don't get new updates in the Office 365 updates node in SCCM Console while updates are visible in WSUS console.

wsyncmgr.log shows for each Office 365 update an error like this :
Synchronizing update ca42e924-de4b-4c25-b43a-05df95a6fe52 - Microsoft 365 Apps Update - Semi-Annual Enterprise Channel Version 2008 for x64 based Edition (Build 13127.21348)
Base Url for Office update file list service not configured or not valid , keep the original Url
ProcessFileManifest() failed to process O365 file manifest. Caught exception: System.Net.WebException: The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel. ---> System.Security.Authentication.AuthenticationException: The remote certificate is invalid according to the validation procedure ...
Failed to synchronize O365 update ca42e924-de4b-4c25-b43a-05df95a6fe52 - Microsoft 365 Apps Update - Semi-Annual Enterprise Channel Version 2008 for x64 based Edition (Build 13127.21348)
STATMSG: ID=6709 SEV=W LEV=M SOURCE="SMS Server" COMP="SMS_WSUS_SYNC_MANAGER" SYS=XXXXXXXXXXX SITE=XXX PID=9128 TID=10472 GMTDATE=mar. juil. 20 15:53:47.462 2021 ISTR0="Microsoft 365 Apps Update - Semi-Annual Enterprise Channel Version 2008 for x64 based Edition (Build 13127.21348)" ISTR1="" ISTR2="" ISTR3="" ISTR4="" ISTR5="" ISTR6="" ISTR7="" ISTR8="" ISTR9="" NUMATTRS=0
Skipped update ca42e924-de4b-4c25-b43a-05df95a6fe52 - Microsoft 365 Apps Update - Semi-Annual Enterprise Channel Version 2008 for x64 based Edition (Build 13127.21348) because it failed to sync.

Nothing have been modified in the settings of the Software Update Point and the ADR.
The whitelist of the endpoints Microsoft seems to be ok and Security team has check the proxy server.
Logs of proxy shows successfull connections on tcp go.microsoft.com 443, tcp sws.update.microsoft.com 443, tcp statsfe2.update.microsoft.com 443 and tcp config.office.com 443.

Any suggestion ?
what can i test / verify on primary site ? ... with IE ?
in the SMS database ?

Microsoft Configuration Manager Updates
Microsoft Configuration Manager Updates
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Updates: Broadly released fixes addressing specific issue(s) or related bug(s). Updates may also include new or modified features (i.e. changing default behavior).
959 questions
0 comments No comments
{count} votes

Accepted answer
  1. LuisOLI 96 Reputation points
    2021-07-21T12:00:54.14+00:00

    Thanks for your answers !
    Finally, someone in my team found the solution : he installed the DigiCert Cloud Services CA-1 certificate on site server and now Office 365 updates are synchronizing by SCCM and showed in SCCM console.


2 additional answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 9,131 Reputation points MVP
    2021-07-20T22:27:25.057+00:00

    Is it just semi-annual channel or all 365 update channels?


  2. HanyunZhu-MSFT 1,841 Reputation points
    2021-07-21T03:02:23.847+00:00

    Hi,

    According to the log content provided, it seems to be a certificate issue.
    Maybe we could try to update the root certificates first. Here is the link:
    https://learn.microsoft.com/en-us/security/trusted-root/release-notes

    Before that, check that the server has not turned off Automatic Root Cert Updates.
    Path: Group Policies > Expand Computer Configuration > Administrative Templates > System > Internet Communication Management > Internet Communication Settings.
    116495-k.png

    For more details, please refer to this similar issue:
    https://social.technet.microsoft.com/Forums/en-US/34c70420-d6f2-4dcf-94fc-ca966de64d81/wsus-server-unable-to-sync-from-microsoft?forum=winserverwsus

    Hope the above information can help you.


    If the response is helpful, please click "Accept Answer"and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.