Hi O'Connell. Claire (Contractor - Tomorrows World),
The behavior you are encountering with your Windows Server 2016 domain controllers is a direct result of a mid-month WSUS metadata revision synchronized by your software update point on June 17th. When Microsoft revises an update's applicability rules, the Configuration Manager client evaluates the new catalog and determines the originally deployed payload is superseded or no longer applicable. This forces the client to report a falsely compliant state for the old deployment while generating a new required entry in your console. You can verify this client-side evaluation shift by reviewing the C:\Windows\CCM\Logs\UpdatesDeployment.log and WUAHandler.log files on an affected domain controller, which will clearly show the update agent ignoring the old deployment ID and requesting the new revision.
To resolve this inconsistency, you must integrate the updated catalog revision into your active deployment infrastructure. Locate the newer instance of the cumulative update in the All Software Updates node that shows a required count but lacks a downloaded status. Download this specific revision and append it to the existing Software Update Group targeting your delayed domain controllers. Once the package successfully replicates to your distribution points, trigger a Machine Policy Retrieval and Evaluation Cycle followed immediately by a Software Updates Deployment Evaluation Cycle on the target servers. This forces the Windows Update Agent to refresh its local policies, recognize the newly approved active revision, and proceed with the installation.
Hope this answer has brought you some useful information. If it did, please hit “accept answer”. Should you have any questions, feel free to leave a comment.
VPHAN