Share via

SCCM Windows Updates

Robert Ostler 1 Reputation point
2022-01-31T13:42:08.087+00:00

Recently, a few Windows servers (W2K12 and W2K19) have stopped detecting monthly updates. They still detect and install AV definitions, but will only download and install monthly updates when manually told to check online for updates. SCCM is correctly configured, and GPEdit.MSC and WindowsUpdate.log confirm that it is looking for the updates in the correct location. Many, but not all of these servers are workgroup servers. 90% of systems are downloading and installing these updates automatically as expected.
Could someone point me at a suitable log, or suggest a reason for this please?
Thank you
Rostler

Microsoft Security | Intune | Configuration Manager | Updates
Windows for business | Windows Server | User experience | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. Limitless Technology 40,106 Reputation points
    2022-01-31T20:10:12.53+00:00

    Hello @Robert Ostler

    I would start checking the requisites are still met, and nothing changed n the workgroup, for example:

    During client installation, the logged-on user must possess local administrator rights on the workgroup system. The only account that Configuration Manager can use to perform activities that require local administrator privileges is the account of the user that is logged on to the computer.

    The Configuration Manager client must be installed from a local source on each client machine. This requirement ensures that a local source for repair and client update application will be available for the client.

    Workgroup clients must be able to locate a server locator point for site assignment because they cannot query Active Directory Domain Services. The server locator point can be manually published in Windows Internet Name Service (WINS), or it can be specified in the CCMSetup.exe installation command-line parameters.

    Workgroup clients must use the Network Access Account to access package source files on distribution points. If a Network Access Account is not configured, clients cannot access content on the distribution point. For more information, see http://technet.microsoft.com/en-us/library/bb932160.aspx

    Although workgroup computers can be Configuration Manager clients, there are inherent limitations in supporting workgroup computers, including the following:

    Workgroup clients cannot locate their default management point from Active Directory Domain Services, and instead must use DNS, WINS, or a server locator point. DNS is recommended for workgroup clients. For more information, see http://technet.microsoft.com/en-us/library/bb632435.aspx

    Active Directory system, user, or user group discovery is not possible.

    User-targeted advertisements are not possible.

    The client push installation method is not supported for workgroup client installation. For more information about installing the Configuration Manager client on workgroup computers, see http://technet.microsoft.com/en-us/library/bb680962.aspx

    Global roaming is not possible. For more information about client roaming capabilities and behavior, see http://technet.microsoft.com/en-us/library/bb632476.aspx

    Using a workgroup client as a branch distribution point is not supported. Configuration Manager requires that all site systems, including branch distribution point computers, are members of an Active Directory domain.

    The out of band management feature is not supported for workgroup computers. For more information about out of band management, see http://technet.microsoft.com/en-us/library/cc161989.aspx

    Hope this helps with your query,

    -----
    --If the reply is helpful, please Upvote and Accept as answer--

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.